Switch language한국어
Back to the list

Millions of AI agents are at risk due to a vulnerability in the open-source package Starlette, which is downloaded more than 300 million times a week

TL;DR AI

Key summary

2 min read
  1. Researchers disclosed CVE-2026-48710, a critical Starlette flaw dubbed BadHost.

  2. A manipulated Host header can bypass routing-based authentication and expose protected endpoints.

  3. Because Starlette underpins tools like FastAPI, MCP, vLLM, and LiteLLM, the impact could spread across many AI agent and server deployments.

  4. Starlette has released a fix, and users are being urged to scan for vulnerable installations and exposed credentials.

Read the original