CVE-2026-48710 "BadHost": The Starlette Host Header Bug Sitting Under Most AI Gateways
CVE-2026-48710, disclosed by X41 D-Sec during an OSTIF-sponsored audit and nicknamed BadHost, lets a single malformed character in an HTTP Host header bypass path-based authentication middleware in Starlette, the ASGI framework underneath FastAPI, vLLM, LiteLLM, and most MCP servers. CISA added it to the KEV catalog on September 2, 2026. The bug sits a layer below the AI gateway a team actually chose, which is the argument for enforcing authorization at the request boundary instead of trusting framework middleware.
Read post →