chiprook
← Security
SecuritySeptember 16, 2026, 15:26

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

A vulnerability CVE-2026-48710 (BadHost) was found in the ASGI framework Starlette (versions 0.8.3–1.0.0): a malformed Host header distorts request.url.path and bypasses path-prefix authorization checks. CISA added it to the exploited vulnerabilities catalog; the fix is Starlette 1.0.1.

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization
#Starlette#FastAPI#LiteLLM#CISA
Read next
Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto

Security

Google Releases AndroidX Libraries for Granular Android Patch Checks

Security

Surfshark: iPhone lets you delete 98% of preinstalled apps, Google only 38%

Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera