Request Smuggling in the ASGI Stack: Starlette and LiteLLM
Request Smuggling in the ASGI Stack: Starlette and LiteLLM Why framework-level parsing flaws travel far A web framework that parses requests incorrectly affects every application built on it, and the fix has to be applied in each of those deployments. Two 2026 CVEs make the point in the Python ecosystem. CVE-2026-48710 in the Kludex Starlette framework is described as HTTP request or response…
Two vulnerabilities discovered in September 2026 affect two popular Python web frameworks used in ASGI deployments. CVE-2026-48710 in Starlette and CVE-2026-59822 in LiteLLM both involve request smuggling flaws that enable authentication bypass attacks.
Request smuggling exploits differences in how a front-end proxy and back-end application parse the same HTTP request bytes. This allows an attacker to construct a request that appears as one request to the proxy but two requests to the application, potentially leading to cache poisoning or authentication bypass. In an ASGI stack, this occurs at the layer boundary where proxy, middleware, and application authentication decisions may disagree about headers like content length and transfer encoding.
The Starlette flaw allows an attacker to impersonate a user's session and gain unauthorized access. LiteLLM, an AI gateway, is even more concerning because it handles credential storage and rate limiting for provider APIs. Improper authentication in LiteLLM enables attackers to consume provider quota, access restricted models, and potentially achieve persistence on the host.
Both CVEs were added to the CISA Known Exploited Vulnerabilities catalog on September 2, 2026, with a remediation deadline of September 16. The remediation for Starlette involves upgrading to a fixed release and ensuring the reverse proxy normalizes request framing. For LiteLLM, upgrading the framework and following standard security practices for internet-facing authentication services are recommended.
The issue highlights the supply chain risk of small framework dependencies that can have far-reaching security impacts. While CISA only published identifying information about the affected versions, organizations need to assess their own Python services and implement the suggested remediation steps to mitigate these vulnerabilities.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.