MEDIUM
litestar-org
CVE published 2026-08-03
CVE-2026-48061
CVE-2026-48061 Litestar Host Header Injection. Litestar versions prior to 2.22.0 are vulnerable to host header injection attacks due to improper handling of X-Forwarded-Host headers. This allows attackers to bypass allowed hosts validation, potentially leading to password reset poisoning, cache poisoning, and server-side request routing manipulation. Litestar users and administrators should assess exposur [truncated]