Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Fedora 44 python-starlette Security Fix for CVE-2026-48710

fedora
Calendar Grey June 5, 2026
Dist Fedora Esm H88
Fix for CVE-2026-48710 in Fedora 44's python-starlette ensures enhanced security and stability.
Backport fix for CVE-2026-48710

Summary

Starlette is a lightweight ASGI framework/toolkit, which is ideal for building

async web services in Python.

It is production-ready, and gives you the following:

• A lightweight, low-complexity HTTP web framework.

• WebSocket support.

• In-process background tasks.

• Startup and shutdown events.

• Test client built on requests.

• CORS, GZip, Static Files, Streaming responses.

• Session and Cookie support.

• 100% test coverage.

• 100% type annotated codebase.

• Few hard dependencies.

• Compatible with asyncio and trio backends.

• Great overall performance against independent benchmarks.

Update Information:

Backport fix for CVE-2026-48710

Change Log

* Thu May 28 2026 Paul Wouters - 0.52.1-2 - Backport fix for CVE-2026-48710

References


[ 1 ] Bug #2481742 - CVE-2026-48710 starlette: Starlette: Security restriction bypass via malformed HTTP Host header https://bugzilla.redhat.com/show_bug.cgi?id=2481742

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3bce8d3f11' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-starlette
Product: Fedora 44
Version: 0.52.1
Release: 2.fc44
Summary: The little ASGI library that shines

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here