Record summary

CVE-2026-48818 has a selected CVSS score of 7.5 (high).

Description

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 73
ProductSourceVersion rangeStatus
CVE List< 1.1.0affected

Exploit Intelligence

Browse Red Hat / Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Migration Toolkit for Applications 8

Browse Red Hat / Migration Toolkit for Applications 8mta/mta-solution-server-rhel9

Default status: unaffected

CVE ListVersion data not supplied

OpenShift Lightspeed

Browse Red Hat / OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9

Default status: unaffected

CVE ListVersion data not supplied

OpenShift Lightspeed

Browse Red Hat / OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/vllm-tpu-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9

Default status: unaffected

CVE ListVersion data not supplied

References

12