Skip to content

fix(deps): bump starlette to 1.0.1 (CVE-2026-48710)#2365

Closed
Odilhao wants to merge 1 commit into
RedHatInsights:foreman-3.18from
Odilhao:fix/cve-2026-48710-starlette-3.18
Closed

fix(deps): bump starlette to 1.0.1 (CVE-2026-48710)#2365
Odilhao wants to merge 1 commit into
RedHatInsights:foreman-3.18from
Odilhao:fix/cve-2026-48710-starlette-3.18

Conversation

@Odilhao
Copy link
Copy Markdown

@Odilhao Odilhao commented May 28, 2026

Bumps starlette to 1.0.1 to fix CVE-2026-48710.

CVE: CVE-2026-48710 — Starlette: Security restriction bypass via malformed HTTP Host header. Missing Host header validation poisons request.url.path, allowing path-based security checks to be bypassed.

Fix version: starlette 1.0.1
Advisory: GHSA-86qp-5c8j-p5mr

@Odilhao
Copy link
Copy Markdown
Author

Odilhao commented May 29, 2026

Closing — requirements regeneration did not follow the correct lockfile tooling procedure. Reopening with correct hashes via pip-compile.

@Odilhao Odilhao closed this May 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant