Researchers have discovered a critical vulnerability in the popular Python framework Starlette. The issue affects FastAPI, vLLM, LiteLLM, and MCP servers for AI agents. Experts warned about the risk of credential theft, SSRF attacks, and remote code execution. Cybersecurity researchers warned about a critical vulnerability called BadHost, which affects millions of servers and AI tools worldwide. The problem was identified in Starlette—a popular open-source Python framework. According to developers, it is downloaded about 325 million times per week. The vulnerability has been assigned the identifier CVE-2026-48710 and affects Starlette versions up to 1.0.1.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned