PatchSiren

litestar-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM litestar-org CVE published 2026-08-03

CVE-2026-48061

CVE-2026-48061 Litestar Host Header Injection. Litestar versions prior to 2.22.0 are vulnerable to host header injection attacks due to improper handling of X-Forwarded-Host headers. This allows attackers to bypass allowed hosts validation, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. Litestar users and administrators should assess exposur [truncated]