CVE-2026-48710

Lưu ý: Dữ liệu này chỉ có tính chất tham khảo, phục vụ nghiên cứu an ninh mạng.CyStack khuyến nghị người dùng không sử dụng các thông tin này nhằm các mục đích bất hợp pháp

Lỗ hổng CVE-2026-48710 là gì?

Lỗ hổng CVE-2026-48710 là lỗ hổng Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') ảnh hưởng tới starlette (phiên bản bị ảnh hưởng: < 1.0.1). Lỗ hổng này được xếp hạng ở mức Trung bình, với điểm CVSS 6.5. Lỗ hổng này đã được ghi nhận khai thác trong thực tế.

Đang phân tích dữ liệu...

Giới thiệu chung

Dữ liệu gốc

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header could make request.url.path differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on request.url (rather than the raw scope path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the Host header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing request.url and falls back to scope["server"] for malformed values.

Sản phẩm và phạm vi ảnh hưởng

Đang phân tích dữ liệu...

Chi tiết kỹ thuật

Đang phân tích dữ liệu...

Khả năng khai thác

Đang phân tích dữ liệu...

Tác động kỹ thuật

Đang phân tích dữ liệu...

Tác động đến tổ chức

Đang phân tích dữ liệu...

Cách khắc phục

Đang phân tích dữ liệu...

Cách phát hiện

Đang phân tích dữ liệu...
Nguồn (35)
Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan