CVE-2026-48710: Kludex Starlette added to CISA KEV
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
Why it matters
The weakness can enable direct compromise with limited attacker prerequisites, making internet-facing assets the first place to look.
What defenders should do
Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.
Verify at the source
CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →
Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security toolsMove from reading to action with the free CyberKit toolbox.