Home / Security / Advisories / NTAP-20260605-0011
NTAP-20260605-0011 — CVE-2026-48710 Starlette Vulnerability in NetApp Products
Published 2026-06-05 · Updated 2026-06-05 · Status: Interim · Exploitation: Public · Severity: MEDIUM 6.5 · ONTAP affected: Yes
Product family: ONTAP · Other NetApp products | ONTAP-relevant | highest CVSS: 6.5
CVEs in this advisory
- CVE-2026-48710 — MEDIUM · CVSS 6.5 · site index
What the CVE records say
CVE-2026-48710 — Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data.
Affected products
- Cloud Volumes ONTAP Mediator
- NetApp Data Classification
- ONTAP tools for VMware vSphere 10
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026