CVE

CVE-2026-48710

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks