REDHAT-BUG-2490020: SSRF

Published Jun 17, 2026
·
Updated

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default followsymlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and followsymlink=True are unaffected. The issue is fixed in 1.1.0.

Affected Software

2 affected components
starlette starlette<=1.0.1
npm/fastapi

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Starlette to a version that resolves this vulnerability.

    Fixed in 1.1.0
  2. Upgrade

    Upgrade StaticFiles on Windows to a version that resolves this vulnerability.

    Fixed in 1.1.0
  3. Configuration

    Ensure the default follow_symlink=False deployment setting is used; the issue affects default follow_symlink=False deployments (POSIX systems and follow_symlink=True are unaffected).

    Starlette/Frameworks built on Starlette (e.g., FastAPI) follow_symlink = false

Event History

Jun 17, 2026
Data Sourced
via Red Hat·07:04 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2490020?

The severity of REDHAT-BUG-2490020 is classified as high with a CVSS score of 7.

2

How do I fix REDHAT-BUG-2490020?

To fix REDHAT-BUG-2490020, upgrade to Starlette version 1.0.2 or later where the vulnerability has been addressed.

3

What type of vulnerability is represented by REDHAT-BUG-2490020?

REDHAT-BUG-2490020 represents an SSRF (Server-Side Request Forgery) vulnerability.

4

Which versions of Starlette are affected by REDHAT-BUG-2490020?

Starlette versions 1.0.1 and earlier are affected by REDHAT-BUG-2490020.

5

What could be exposed due to the vulnerability in REDHAT-BUG-2490020?

The vulnerability in REDHAT-BUG-2490020 could expose the service account's NTLM credentials due to an outbound SMB connection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203