BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass

rank 0 · 0 points · 1 sources · primary Hacker News Front Page

open source

Summary

A critical severity vulnerability (CVE-2026-48710) was discovered in Starlette <0.1, allowing attackers to forge request URLs and bypass path-based authentication middleware. Thousands of FastAPI and Starlette applications are affected, including AI infrastructure.

Why it matters

Critical

Related coverage

Hacker News Front PageBadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass5/27/2026, 5:45:42 PM

Post Stream

Flat, source-grounded posts. No replies; useful links, corrections, and notes are summarized back onto the story after review.

Local fixture mode allows posting. Production posting requires Google login and write-rate limits.

No posts have been added to this cluster yet.

Rank history