{"id":"GHSA-wqp7-x3pw-xc5r","summary":"Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows","details":"### Summary\n\nWhen serving static files on Windows, `StaticFiles` resolves the requested path with [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). If a UNC path (such as `\\\\attacker.com\\share`) reaches the resolver, `realpath` causes the process to open a connection to the remote host over SMB (port 445). This is a server-side request forgery (SSRF) that leaks the service account's NTLMv2 credentials to the attacker-controlled host, which can then be cracked offline or relayed to other hosts.\n\n### Details\n\n`StaticFiles.lookup_path()` joins the requested path onto the served directory and calls [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath) on the result before checking containment with [`os.path.commonpath`](https://docs.python.org/3/library/os.path.html#os.path.commonpath). On Windows, a UNC path is absolute, so [`os.path.join`](https://docs.python.org/3/library/os.path.html#os.path.join) discards the served directory and `realpath` resolves the bare UNC path, triggering the outbound SMB connection and NTLM authentication before the containment check rejects the path. The HTTP response is a benign 404, but the credential disclosure has already happened. POSIX systems are not affected.\n\nThis only affects the default configuration (`follow_symlink=False`), which uses [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). The `follow_symlink=True` branch uses [`os.path.abspath`](https://docs.python.org/3/library/os.path.html#os.path.abspath), which performs no I/O.\n\n### Impact\n\nApplications running on Windows that serve files with `StaticFiles` (directly, or via a framework built on Starlette such as FastAPI) in the default configuration are affected. `StaticFiles` is typically unauthenticated, so any client can trigger the SMB connection and leak the service account's NTLMv2 hash. A secondary impact is discovering internal hosts reachable over SMB by timing responses for valid versus invalid addresses.\n\n### Mitigation\n\nApplications not running on Windows are not affected. On Windows, serving static files through a dedicated web server (such as nginx or IIS) instead of `StaticFiles` avoids the issue. Blocking outbound SMB (port 445) from the application host prevents the credential disclosure even if a UNC path is resolved.","aliases":["CVE-2026-48818","PYSEC-2026-2281"],"modified":"2026-07-17T21:05:11.272813617Z","published":"2026-06-15T20:16:30Z","database_specific":{"github_reviewed_at":"2026-06-15T20:16:30Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-wqp7-x3pw-xc5r"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"}],"affected":[{"package":{"name":"starlette","ecosystem":"PyPI","purl":"pkg:pypi/starlette"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"versions":["0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.10.0","0.10.1","0.10.2","0.10.3","0.10.4","0.10.5","0.10.6","0.10.7","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.12.0","0.12.0b1","0.12.0b2","0.12.0b3","0.12.1","0.12.10","0.12.11","0.12.12","0.12.13","0.12.2","0.12.3","0.12.4","0.12.5","0.12.6","0.12.7","0.12.8","0.12.9","0.13.0","0.13.1","0.13.2","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.13.8","0.14.0","0.14.1","0.14.2","0.15.0","0.16.0","0.17.0","0.17.1","0.18.0","0.19.0","0.19.1","0.2.0","0.2.1","0.2.2","0.2.3","0.20.0","0.20.1","0.20.2","0.20.3","0.20.4","0.21.0","0.22.0","0.23.0","0.23.1","0.24.0","0.25.0","0.26.0","0.26.0.post1","0.26.1","0.27.0","0.28.0","0.29.0","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7","0.30.0","0.31.0","0.31.1","0.32.0","0.32.0.post1","0.33.0","0.34.0","0.35.0","0.35.1","0.36.0","0.36.1","0.36.2","0.36.3","0.37.0","0.37.1","0.37.2","0.38.0","0.38.1","0.38.2","0.38.3","0.38.4","0.38.5","0.38.6","0.39.0","0.39.1","0.39.2","0.4.0","0.4.1","0.4.2","0.40.0","0.41.0","0.41.1","0.41.2","0.41.3","0.42.0","0.43.0","0.44.0","0.45.0","0.45.1","0.45.2","0.45.3","0.46.0","0.46.1","0.46.2","0.47.0","0.47.1","0.47.2","0.47.3","0.48.0","0.49.0","0.49.1","0.49.2","0.49.3","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.5.5","0.50.0","0.51.0","0.52.0","0.52.1","0.6.0","0.6.1","0.6.2","0.6.3","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","0.8.6","0.8.7","0.8.8","0.9.0","0.9.1","0.9.10","0.9.11","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","1.0.0","1.0.0rc1","1.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-wqp7-x3pw-xc5r/GHSA-wqp7-x3pw-xc5r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}