Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54282

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header or scope) can therefore be misled into trusting an attacker-supplied host. This vulnerability is fixed in 1.3.0.

A flaw was found in Starlette, a lightweight Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.3.0, the HTTP request path was not properly validated when reconstructing the request.url. A remote attacker could craft a malicious HTTP request path that does not begin with a forward slash, causing the framework to misinterpret the authority boundary. This could lead to request.url.hostname and request.url.netloc becoming attacker-controlled, potentially misleading applications that rely on these values into trusting an attacker-supplied host.

Отчет

Red Hat rates this issue as having Low impact for Red Hat AI products. Bundled Starlette versions in Red Hat OpenShift AI, Red Hat AI Inference Server, and Red Hat Enterprise Linux AI are either not vulnerable or the flawed path validation is not reachable in supported deployments.

Меры по смягчению последствий

No mitigation required for unaffected deployments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-sandbox-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2491467starlette: Starlette: Information disclosure due to improper HTTP request path validation

EPSS

Процентиль: 9%
0.00187
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header or scope) can therefore be misled into trusting an attacker-supplied host. This vulnerability is fixed in 1.3.0.

CVSS3: 3.7
nvd
около 1 месяца назад

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header or scope) can therefore be misled into trusting an attacker-supplied host. This vulnerability is fixed in 1.3.0.

CVSS3: 3.7
debian
около 1 месяца назад

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the ...

CVSS3: 3.7
github
около 2 месяцев назад

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

suse-cvrf
около 1 месяца назад

Security update for python-starlette

EPSS

Процентиль: 9%
0.00187
Низкий

4.8 Medium

CVSS3