---
schema_version: '1.0'
id: security-20260714-52fc4b
url: https://osv.dev/vulnerability/PYSEC-2026-2280
url_hash: 52fc4be61e79f1d6305ec38ac7765ffb03e6e205a137895a7bf380391dfabbb0
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2280
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-48817
- PYSEC-2026-2280
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- starlette
- PyPI
lang: en
published_at: '2026-06-17T20:17:22Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:44:25Z'
status: published
content_hash: 600872f422f27067e5207b726924ae08701be1b1e1b8ef0579c4df1a7fc19fa6
license_note: full
summary: Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and
  below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing
  the HTTP method and looking it up as an attribute with getattr, without restricting
  the lookup to a known set of HTTP verbs.
summary_source: rss
summary_en: Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and
  below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing
  the HTTP method and looking it up as an attribute with getattr, without restricting
  the lookup to a known set of HTTP verbs.
entities:
- name: Starlette
  type: organization
key_facts: []
related: []
related_auto:
- name: Hermes
  type: artifact
  weight: 2.0
- name: hermes
  type: concept
  weight: 1.0
title: CVE-2026-48817 — starlette
---

# CVE-2026-48817 — starlette

## TL;DR
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs.

## Key Points
- cve / CVE-2026-48817 / PYSEC-2026-2280 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N / starlette / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
**Advisory:** PYSEC-2026-2280 (CVE-2026-48817)

**Affected (your watchlist):**
- `PyPI:starlette` 0.41.3 → fixed in 1.1.0 [docker/docker-portal]
- `PyPI:starlette` 1.0.0 → fixed in 1.1.0 [docker/local]

**Details:**
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lowercased name matches an attribute on the endpoint subclass reaches the endpoint, that attribute is invoked as if it were a request handler. An attacker can use this to reach methods that were never meant to be HTTP handlers, such as internal helpers, without the authorization checks applied by the intended public handler. An application (including Starlette-based frameworks like FastAPI) is affected if it registers an HTTPEndpoint subclass via Route(...) without explicitly setting methods=, and that subclass includes extra methods named like non-standard HTTP verbs that take one request argument and return a response. This issue has been fixed in version 1.1.0.

**References:**
- https://github.com/Kludex/starlette/releases/tag/1.1.0
- https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2280_

## Source
元記事: [CVE-2026-48817 — starlette](https://osv.dev/vulnerability/PYSEC-2026-2280) — published 2026-06-17T20:17:22Z
