CVE-2026-48710
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.
CISA federal remediation date Sep 16
Vulnerabilities · 134 days ago
A single Host header trick can slip past Starlette’s path-based authorization and turn trusted AI and app integrations into a credential leak. In FastAPI and the Python tooling built on Starlette, that means an attacker can reach protected endpoints and pull third-party account secrets instead of just poking one server.
The flaw is CVE-2026-48710, BadHost, and it affects Starlette versions prior to 1.0.1. Ars Technica says the blast radius runs through FastAPI and into vLLM, LiteLLM, Text Generation Inference, OpenAI-shim proxies, MCP servers, agent harnesses, eval dashboards, and model-management UIs, where stored email, calendar, database, and SaaS credentials can be exposed.
For teams running MCP-connected services, patching the framework fixes the entry point but does not undo any secrets already reached through it. The risk is account takeover through trusted integrations, not a single compromised host.
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.
CISA federal remediation date Sep 16
1 source covering this story
Millions of AI agents imperiled by critical vulnerability in open source package
BadHost" was found in Starlette, a package with 325 million weekly downloads.
Part of the PlainSec briefing for 2026-05-27