CVE-2026-48817Medium· 5.3▾ SunlitStarlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
When dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs.
When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lowercased name matches an attribute on the endpoint subclass reaches the endpoint, that attribute is invoked as if it were a request handler. An attacker can use this to reach methods that were never meant to be HTTP handlers, such as internal helpers, without the authorization checks applied by the intended public handler.
HTTPEndpoint uses the client-supplied method name to resolve an instance attribute, without validating it against the set of HTTP verbs the endpoint supports. A method such as _DO_DELETE therefore resolves an attribute like _do_delete and invokes it. Non-standard methods are valid RFC 9110 token methods, so an endpoint must not treat the method name as a trusted attribute selector.
An application is affected when all of the following hold:
HTTPEndpoint subclass and registers it via Route(...) without an explicit methods= argument.request argument and return a response.This also affects frameworks built on Starlette, like FastAPI.
Register HTTPEndpoint subclasses with an explicit methods= argument on the Route, listing only the HTTP verbs the endpoint supports. The route then rejects any other method with 405 Method Not Allowed before it reaches the endpoint, so non-standard methods cannot resolve an attribute.
starlette < 1.1.0Upgrade to a patched release:
starlette 1.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62727High· 7.5Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
CVE-2026-48818High· 7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVE-2026-54282Low· 3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-48710Medium· 6.5Starlette is a lightweight ASGI framework/toolkit
CVE-2023-29159Low· 3.7Starlette has Path Traversal vulnerability in StaticFiles
CVE-2024-47874None· 0.0Starlette Denial of service (DoS) via multipart/form-data