Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-48061— Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

Quick assessment

Affected
litestar-org litestar
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Litestar是Litestar组织开源的一款基于Python的异步Web开发框架。 Litestar 2.22.0之前版本存在跨站脚本漏洞,该漏洞源于AllowedHostsMiddleware在缺少Host标头时信任客户端可控的X-Forwarded-Host标头作为回退,导致攻击者可以绕过允许主机验证,发起主机标头注入攻击,如密码重置投毒、缓存投毒和服务端请求路由操纵。

CVSS 5.9 · Medium EPSS 0.38% · P29

Affected Version Matrix 1

VendorProduct Version RangeStatus
litestar-org litestar < 2.22.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48061

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
Source: CVE Program / CVE List V5
Vulnerability Description
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对HTTP头部进行脚本语法转义处理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Litestar 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Litestar是Litestar组织开源的一款基于Python的异步Web开发框架。 Litestar 2.22.0之前版本存在跨站脚本漏洞,该漏洞源于AllowedHostsMiddleware在缺少Host标头时信任客户端可控的X-Forwarded-Host标头作为回退,导致攻击者可以绕过允许主机验证,发起主机标头注入攻击,如密码重置投毒、缓存投毒和服务端请求路由操纵。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
litestar-org litestar < 2.22.0 -

II. Public POCs for CVE-2026-48061

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48061

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-48061 (1)

Vendor Advisories for CVE-2026-48061 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-48061

No comments yet


Leave a comment