PatchSiren cyber security CVE debrief
CVE-2026-48061 litestar-org CVE debrief
CVE-2026-48061 Litestar Host Header Injection. Litestar versions prior to 2.22.0 are vulnerable to host header injection attacks due to improper handling of X-Forwarded-Host headers. This allows attackers to bypass allowed hosts validation, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. Litestar users and administrators should assess exposure and prioritize remediation by updating to version 2.22.0 or later and configuring reverse proxies to strip X-Forwarded-Host headers.
- Vendor
- litestar-org
- Product
- litestar
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-09-10
Who should care
Litestar users and administrators should assess exposure and prioritize remediation. This includes reviewing and updating Litestar to version 2.22.0 or later, configuring reverse proxies to strip X-Forwarded-Host headers, and monitoring for suspicious HTTP/1.0 connections. Security teams and operators managing Litestar deployments should verify affected scope and implement mitigations.
Why it matters
CVE-2026-48061 is a medium-severity vulnerability in Litestar that allows host header injection attacks, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. Litestar users and administrators should assess exposure and prioritize remediation by updating to version 2.22.0 or later and configuring reverse proxies to strip X-Forwarded-Host headers. The vulnerability requires verification of affected versions and deployment contexts.
- Password reset poisoning is a potential consequence of this vulnerability
- Cache poisoning is a potential consequence of this vulnerability
- Server-side request routing manipulation is a potential consequence of this vulnerability
Technical summary
Litestar versions prior to 2.22.0 are vulnerable to host header injection attacks due to improper handling of X-Forwarded-Host headers. This allows attackers to bypass allowed hosts validation, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. The vulnerability requires verification of affected versions and deployment contexts. Updating to version 2.22.0 or later and configuring reverse proxies to strip X-Forwarded-Host headers can mitigate the vulnerability.
Defensive priority
Medium priority for Litestar users
Recommended defensive actions
- Review and update Litestar to version 2.22.0 or later
- Configure reverse proxies to strip X-Forwarded-Host headers
- Monitor for suspicious HTTP/1.0 connections
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the host header injection vulnerability in Litestar versions prior to 2.22.0. Evidence is limited to public CVE and NVD sources. Defenders should verify affected versions, deployment contexts, and configurations to assess exposure. Review official advisories and CVE records for source-provided details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48061 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48061
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48061 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48061
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/litestar-org/litestar/commit/6930a20ceb543912cd651b42deae5b9f3637a262
-
Source reference
Unverified legacy reference
URL: https://github.com/litestar-org/litestar/security/advisories/GHSA-3qmc-cj7q-62hv
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.