๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Summary
Kludex Starlette contains an HTTP request/response smuggling vulnerability (a technique where attackers manipulate how web servers process requests and responses) that allows attackers to inject malicious paths into the host part of a URL, potentially bypassing authentication systems that rely on checking the URL's path. This vulnerability is being actively exploited by attackers in the wild.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance on prioritizing security updates. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each system's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-09-16.
Vulnerability Details
EPSS: 2.1%
Yes
๐ฅ Actively Exploited
September 1, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48710
First tracked: September 2, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 75%