BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
↗Critical Starlette vulnerability CVE-2026-48710 (BadHost) enables Host header-based path auth bypass in Starlette <1.0.1, affecting thousands of AI infra apps; fix by upgrading to 1.0.1+, adopting endpoint-based security, and placing a reverse proxy in front of ASGI servers.
May 27, 20261%