{"id":"CVE-2026-48061","aliases":["GHSA-3qmc-cj7q-62hv","PYSEC-2026-2603"],"url":"https://o3.security/vulnerability/CVE-2026-48061","summary":"Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header","details":"Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.","published":"2026-08-03T20:47:34.673Z","modified":"2026-08-12T03:51:15.371753365Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00283,"percentile":0.20391,"asOf":"2026-09-02"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"litestar","fixedVersion":"2.22.0"}],"fix":{"url":"https://github.com/litestar-org/litestar/commit/6930a20ceb543912cd651b42deae5b9f3637a262","label":"litestar-org/litestar@6930a20"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48061.json"},{"type":"ADVISORY","url":"https://github.com/litestar-org/litestar/security/advisories/GHSA-3qmc-cj7q-62hv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48061"},{"type":"FIX","url":"https://github.com/litestar-org/litestar/commit/6930a20ceb543912cd651b42deae5b9f3637a262"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.371753365Z"}}