PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48061 litestar-org CVE debrief

CVE-2026-48061 Litestar Host Header Injection. Litestar versions prior to 2.22.0 are vulnerable to host header injection attacks due to improper handling of X-Forwarded-Host headers. This allows attackers to bypass allowed hosts validation, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. Litestar users and administrators should assess exposure and prioritize remediation by updating to version 2.22.0 or later and configuring reverse proxies to strip X-Forwarded-Host headers.

Vendor
litestar-org
Product
litestar
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-09-10
Advisory published
2026-08-03
Advisory updated
2026-09-10

Who should care

Litestar users and administrators should assess exposure and prioritize remediation. This includes reviewing and updating Litestar to version 2.22.0 or later, configuring reverse proxies to strip X-Forwarded-Host headers, and monitoring for suspicious HTTP/1.0 connections. Security teams and operators managing Litestar deployments should verify affected scope and implement mitigations.

Why it matters

CVE-2026-48061 is a medium-severity vulnerability in Litestar that allows host header injection attacks, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. Litestar users and administrators should assess exposure and prioritize remediation by updating to version 2.22.0 or later and configuring reverse proxies to strip X-Forwarded-Host headers. The vulnerability requires verification of affected versions and deployment contexts.

  • Password reset poisoning is a potential consequence of this vulnerability
  • Cache poisoning is a potential consequence of this vulnerability
  • Server-side request routing manipulation is a potential consequence of this vulnerability

Technical summary

Litestar versions prior to 2.22.0 are vulnerable to host header injection attacks due to improper handling of X-Forwarded-Host headers. This allows attackers to bypass allowed hosts validation, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. The vulnerability requires verification of affected versions and deployment contexts. Updating to version 2.22.0 or later and configuring reverse proxies to strip X-Forwarded-Host headers can mitigate the vulnerability.

Defensive priority

Medium priority for Litestar users

Recommended defensive actions

  • Review and update Litestar to version 2.22.0 or later
  • Configure reverse proxies to strip X-Forwarded-Host headers
  • Monitor for suspicious HTTP/1.0 connections
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the host header injection vulnerability in Litestar versions prior to 2.22.0. Evidence is limited to public CVE and NVD sources. Defenders should verify affected versions, deployment contexts, and configurations to assess exposure. Review official advisories and CVE records for source-provided details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48061 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48061

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48061 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48061

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.