CVE detail
CVE-2026-48818
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48818.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 17, 2026, 7:18 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2490020bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 17, 2026, 7:18 PM - https://access.redhat.com/security/cve/CVE-2026-48818access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 7:18 PM - https://access.redhat.com/errata/RHSA-2026:30089access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 7:18 PM - https://access.redhat.com/errata/RHSA-2026:30088access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 7:18 PM - https://access.redhat.com/errata/RHSA-2026:30087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 17, 2026, 7:18 PM No excerpt available.
Exploitgithub.comJun 17, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJun 17, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJun 17, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJun 17, 2026, 7:18 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-54249CVSS 6.8 · Medium
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message his…
- CVE-2026-46678CVSS 6.8 · Medium
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local…
- CVE-2026-67436CVSS 8.3 · High
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URL…
- CVE-2026-67435CVSS 6.0 · Medium
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirect…
- CVE-2026-67428CVSS 8.5 · High
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py,…
- CVE-2026-67426CVSS 9.3 · Critical
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes un…