host-header

Tag

Cards List
#host-header

CVE-2026-48710 Starlette Host-Header Auth Bypass

Lobsters Hottest · 2026-05-27 Cached

A critical host-header authentication bypass vulnerability (CVE-2026-48710) in Starlette and FastAPI affects many Python ASGI applications, including AI inference servers (e.g., vLLM), AI proxy servers (e.g., LiteLLM), and MCP gateways, potentially allowing unauthorized access.

0 favorites 0 likes
← Back to home

Submit Feedback