Millions of AI agents are at risk due to a vulnerability in the open-source package Starlette, which is downloaded more than 300 million times a week

TL;DR AI
2 min readKey summary
Researchers disclosed CVE-2026-48710, a critical Starlette flaw dubbed BadHost.
A manipulated Host header can bypass routing-based authentication and expose protected endpoints.
Because Starlette underpins tools like FastAPI, MCP, vLLM, and LiteLLM, the impact could spread across many AI agent and server deployments.
Starlette has released a fix, and users are being urged to scan for vulnerable installations and exposed credentials.



