
A vulnerability tracked as CVE-2026-48710 and named BadHost affects Starlette, an open source framework that receives 325 million downloads per week, along with widely used packages including FastAPI, vLLM, and LiteLLM. A single character injected into the HTTP Host header bypasses path-based authorization.
Starlette is the base of frameworks for building services in Python apps and underpins MCP (model context protocol) servers, which allow AI agents to access external systems including user databases, email and calendar accounts. MCP servers store credentials for these systems, making them targets for attackers seeking sensitive data and third-party account credentials.
BadHost carries a severity rating of 7 out of 10 according to Secwest, though X41 D-Sec, the security firm that discovered it, described it as having critical severity. The vulnerability affects Starlette versions prior to 1.0.1, which was released Friday.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
CBTS Technology Solutions LLC launched Forge Agents, a platform that turns a plain-language job description in…
Imec CEO Patrick Vandenameele said at SEMICON Taiwan 2026 that the Belgian research center is broadening its c…

Alphabet's AI Overviews now reach over 2.5 billion monthly users through Google Search, and its ad business ge…

Amazon Web Services (AWS) has integrated its fully managed data warehouse service, Amazon Redshift, with Agent…

Visual Studio Code 1.135 now includes an experimental 'Rubber Duck' feature that lets developers request a sec…

Sonos announced a new app update with generative AI features, a new soundbar called the Beam Ultra, and its se…
