
CVE-2026-48818 Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\http://attacker.com\sha… https://www.cve.org/CVERecord?id=CVE-2026-48818
Post summary
The text announces a Server‑Side Request Forgery vulnerability in Starlette StaticFiles on Windows, affecting versions 1.0.1 and earlier, triggered by UNC paths.
