CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Summary

Kludex Starlette has a HTTP request/response smuggling vulnerability that can allow attackers to inject paths, potentially leading to authentication bypass. This vulnerability can be chained with CVE-2026-42271, and CISA mandates mitigation actions and adherence to patching guidelines by a specific federal due date.

IFF Assessment

FOE

The identified vulnerability allows for authentication bypass and can be chained with other exploits, posing a direct threat to systems and data.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 16, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Kludex Starlette presents a significant risk for authentication bypass, which could be exploited to gain unauthorized access. Defenders should prioritize applying vendor-provided mitigations and follow CISA's guidance on risk-based patching, especially for internet-exposed assets.

Read Full Story →