BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass | Hacker News
TL;DR AI
2 min readKey summary
Starlette has an advisory for a host-header authentication bypass, tracked as CVE-2026-48710.
The issue may affect many downstream Python services and AI infrastructure built on Starlette, including FastAPI and related stacks.
Potentially impacted deployments include LLM and MCP servers such as vLLM, LiteLLM, and MCP gateways, especially where host-header checks are trusted.
Patching should be prioritized for production systems that rely on vulnerable Starlette configurations, including setups behind Cloudflare or AWS ALB.



