starlette

Tag

Cards List
#starlette

CVE-2026-48710: A Maintainer's Perspective

Lobsters Hottest ↗ · 2026-05-29 Cached

Marcelo Trylesinski shares his perspective on CVE-2026-48710, a security vulnerability in Starlette involving path-based authorization bypass via manipulated Host headers. He argues the vulnerability stems from application patterns and deployment, not the framework itself.

0 favorites 0 likes
#starlette

CVE-2026-48710 Starlette Host-Header Auth Bypass

Lobsters Hottest ↗ · 2026-05-27 Cached

A critical host-header authentication bypass vulnerability (CVE-2026-48710) in Starlette and FastAPI affects many Python ASGI applications, including AI inference servers (e.g., vLLM), AI proxy servers (e.g., LiteLLM), and MCP gateways, potentially allowing unauthorized access.

0 favorites 0 likes
#starlette

Millions of AI agents imperiled by critical vulnerability in open source package

Ars Technica ↗ · 2026-05-26 Cached

A critical vulnerability (CVE-2026-48710, named BadHost) in the open-source ASGI framework Starlette exposes millions of AI agents and servers to potential data theft and credential compromise, affecting frameworks like FastAPI, vLLM, and LiteLLM. Patched in Starlette 1.0.1, the flaw is trivial to exploit and underscores risks in the AI tooling ecosystem.

0 favorites 0 likes
← Back to home

Submit Feedback