Kludex Starlette contains an HTTP request/response smuggling vulnerability tracked as CVE-2026-48710. The flaw allows attackers to inject paths into the host part of a request, prepending the actual path and potentially causing authentication bypass when authentication logic depends on the reconstructed URL path. This vulnerability can be chained with CVE-2026-42271 to amplify impact. It affects an open-source component that may be used by a wide range of products and implementations. CISA has catalogued this vulnerability under BOD 26-04, which prioritizes security updates based on risk. A security advisory has been published on GitHub by Kludex. Organizations using Starlette-based applications should apply patches promptly. The vulnerability is rated High criticality.