Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being use
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
등재일 2026. 09. 02.
패치 기한 2026. 09. 16.
즉시(3일 이내) 패치 — 최우선 대응
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N상세 설명
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header could make request.url.path differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on request.url (rather than the raw scope path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the Host header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing request.url and falls back to scope["server"] for malformed values.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- encode starlette0.8.3 - 1.0.1other
- redhat ai_inference_server3.3.0 - 3.3.5linux
- redhat ansible_automation_platformlinux
- redhat ansible_automation_platformlinux
- redhat migration_toolkit_for_applications< 8.2.0linux
- redhat openshift_ai3.3 - 3.3.5linux
- redhat openshift_ai3.4 - 3.4.2linux
- redhat openshift_lightspeedlinux
- redhat satellitelinux
- redhat satellitelinux
- redhat satellitelinux
- redhat enterprise_linux_ailinux
영향받는 구성 (CPE) 11
- encode starlette≥ 0.8.3 < 1.0.1cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*
- redhat ai_inference_server≥ 3.3.0 ≤ 3.3.5cpe:2.3:a:redhat:ai_inference_server:*:*:*:*:*:*:*:*
- redhat ansible_automation_platform 2.6cpe:2.3:a:redhat:ansible_automation_platform:2.6:-:*:*:*:*:*:*
- redhat ansible_automation_platform 2.7cpe:2.3:a:redhat:ansible_automation_platform:2.7:-:*:*:*:*:*:*
- redhat migration_toolkit_for_applications< 8.2.0cpe:2.3:a:redhat:migration_toolkit_for_applications:*:*:*:*:*:*:*:*
- redhat openshift_ai≥ 3.3 < 3.3.5cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:*
- redhat openshift_lightspeedcpe:2.3:a:redhat:openshift_lightspeed:-:*:*:*:*:*:*:*
- redhat satellite 6.17cpe:2.3:a:redhat:satellite:6.17:*:*:*:*:*:*:*
- redhat satellite 6.18cpe:2.3:a:redhat:satellite:6.18:*:*:*:*:*:*:*
- redhat satellite 6.19cpe:2.3:a:redhat:satellite:6.19:*:*:*:*:*:*:*
- redhat enterprise_linux_ai 3.0cpe:2.3:o:redhat:enterprise_linux_ai:3.0:*:*:*:*:*:*:*
참고 자료 29
- https://badhost.orgMitigationThird Party Advisory
- https://ostif.org/disclosing-the-badhost-vulnerability-in-starletteMitigationThird Party Advisory
- https://www.secwest.net/starletteExploitMitigationThird Party Advisory
- https://www.x41-dsec.de/lab/advisories/x41-2026-002-starletteExploitMitigationThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:22992Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:22993Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:23346Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:24866Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:26226Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30088Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30089Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:34456Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:34526Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:34532Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:37275Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:43038Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44696Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:51357Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:60520Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:63337Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-48710Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2481742Issue TrackingThird Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.jsonThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48710Third Party AdvisoryUS Government Resource
- https://www.wiz.io/blog/ai-infrastructure-honeypotExploitThird Party Advisory
링크 내용 불러오는 중…