
A vulnerability tracked as CVE-2026-48710 and named BadHost affects Starlette, an open source framework that receives 325 million downloads per week, along with widely used packages including FastAPI, vLLM, and LiteLLM. A single character injected into the HTTP Host header bypasses path-based authorization.
Starlette is the base of frameworks for building services in Python apps and underpins MCP (model context protocol) servers, which allow AI agents to access external systems including user databases, email and calendar accounts. MCP servers store credentials for these systems, making them targets for attackers seeking sensitive data and third-party account credentials.
BadHost carries a severity rating of 7 out of 10 according to Secwest, though X41 D-Sec, the security firm that discovered it, described it as having critical severity. The vulnerability affects Starlette versions prior to 1.0.1, which was released Friday.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd