Vulnerability in open-source component puts AI platforms at risk

TL;DR AI
2 min readKey summary
Researchers found BadHost, a Starlette vulnerability that can let attackers manipulate the HTTP Host header and bypass host-based access controls.
The flaw, tracked as CVE-2026-48710, affects stacks built on Starlette, including FastAPI, vLLM, LiteLLM, and Model Context Protocol tooling.
Because many AI platforms and agent systems use these components, the bug could expose internal tools, API keys, and sensitive corporate data.
Starlette 1.0.1 includes a fix, and developers using downstream frameworks are being urged to patch quickly.
