CVE-2026-48710 Starlette Host-Header Auth Bypass (opens in new tab)
Scan your Starlette or FastAPI server for CVE-2026-48710 (BadHost): a critical auth bypass via Host header injection affecting MCP servers, LLM proxies, AI agent frameworks, and thousands of Python ASGI applications.
Read the original article