Request Smuggling in the ASGI Stack: Starlette and LiteLLM
Request Smuggling in the ASGI Stack: Starlette and LiteLLM Why framework-level parsing flaws travel far A web framework that parses requests incorrectly affects every application built on it, and the fix has to be applied in each of those deployments. Two 2026 CVEs make the point in the Python ecosystem. CVE-2026-48710 in the Kludex Starlette framework is described as HTTP request or response smuggling leading to authentication bypass, and CVE-2026-59822 in BerriAI LiteLLM is described as improper authentication. Both were added to CISA's Known Exploited Vulnerabilities catalog on 2 September
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in