Reposted by Insecurity Connoisseur
🚨CVE-2026-48710("BadHost"): one character in a Host header bypasses path-based authorization across most of the Python AI stack.
Lives in Starlette, reaches FastAPI and through it: vLLM (where it was discovered), LiteLLM, TGI, MCP servers, agent harnesses, eval dashboards.
cc
@marver.bsky.social
secwest.net
starlette - secwest.net - secure virtual engagement