Security News

Cybersecurity news aggregator

🐧
MEDIUM Updates Debian Security

DSA-6302-1 starlette - security update

  • What: Security update for Starlette with Host header validation flaw
  • Impact: Debian users should update to prevent security check bypass
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6302-1] starlette security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6302-1] starlette security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Wed, 27 May 2026 21:01:47 +0000 Message-id: <[🔎] ahdbu63CmRxPQi3N@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6302-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 27, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : starlette CVE ID : CVE-2026-48710 It was discovered that missing validation of Host: headers in the Starlette ASGI framework could result in a bypass of security checks. For the oldstable distribution (bookworm), this problem has been fixed in version 0.26.1-1+deb12u1. This update also resolves three additional security issues (CVE-2023-29159, CVE-2024-47874 and CVE-2025-54121). For the stable distribution (trixie), this problem has been fixed in version 0.46.1-3+deb13u2. We recommend that you upgrade your starlette packages. For the detailed security status of starlette please refer to its security tracker page at: https://security-tracker.debian.org/tracker/starlette Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoXW0EACgkQEMKTtsN8 TjY+ag/+O8tstfVtSSZuDSgaCls7kFVg8Z9gggUT2qoSExb6+/sYbAmcu9b7dy3C vNjnvMx6ADI7yAFrZcrqMyx8wh51i777evfEbCtJL3gvAB1sp9uZUmaya7S3QUQe pI1FssQ4OdFaXdtLd/1r109i6kMRaUoeprkfMM1WFRYz+GrEOW4EWeYIYARBDgic rFLtPmsAEcS0SiEZzXbOkgc3cZp0yUIogEUsOfgp5eWREMWrdPRTnok1hgVz2j7V Z98MqFSkAMNGL6yERR2lgwyAp49M3M4I7V1uU8/m7CXIDYcouM7cxZUBVJfl3y7c hH+9RZ2klmXpLvljF5TqDtuJA2iRZfhxvtSMUCH/2/3zG7Ulr75B59qOSazgXJd1 rJjfeOKuJqpanDOObYPzANXpGx8O/EPBp57ghoeOiwvYDCNvxG6hg2ypv+d0LSMq FhQ3cceaJoS+9q/gWcJ15cRhVzAZtlLhZQvJ5qcJbRG5X3Pvt37iO7y46MgjRXzk IIWXfvdukVh2AYBBAdXZc4T06RM34a1wAwa/suRIshbPwQlrY6x+s4uJWJd9/NwU fueDb0dZ5Rqh7czX0Yl5q2El2lh9sHsjNEFH1+nB38THuY1vxrS1QgQy9uzEP3PV wu3xpEFXMWIKROMuvPF6sHeDi/Ji6S1XxZy8q7Xflu5nZeQByBg= =+wvi -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6301-1] roundcube security update Next by Date: [SECURITY] [DSA 6303-1] varnish security update Previous by thread: [SECURITY] [DSA 6301-1] roundcube security update Next by thread: [SECURITY] [DSA 6303-1] varnish security update Index(es): Date Thread

Share this article