Get the latest tech news

BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass


Scan your Starlette or FastAPI server for CVE-2026-48710 (BadHost): a critical auth bypass via Host header injection affecting MCP servers, LLM proxies, AI agent frameworks, and thousands of Python ASGI applications.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of cve-2026

cve-2026

Photo of starlette

starlette

Photo of header auth bypass

header auth bypass

Related news:

News photo

CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude

News photo

Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim

News photo

"Dirty Frag" (CVE-2026-43284): The Second Linux Root Exploit in Eight Days