VDB

CVE-2026-48710

CVE-2026-48710 PUBLISHED KEV CVSS 6.5 MEDIUM

CVE-2026-48710, also known as BadHost, is a vulnerability affecting Starlette versions prior to 1.0.1. A lack of input sanitization on host header paths in Starlette leads to bypassing authentication with a single character across a large swath of Python LLM infrastructure including very large and prominent projects such as FastAPI, LiteLLM, vLLM, text generation inference projects, most OpenAI shim proxies, MCP servers, Agent harnesses, eval dashboards, and model-management UIs. In affected versions, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header could make request.url.path differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on request.url (rather than the raw scope path) could therefore be bypassed. A successful attacker could exploit BadHost to gain access to sensitive data and exfiltrate credentials used by third-party accounts.

EPSS 1.91% · 78.1th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
1.91%
78.1th percentile

Affected Products

VendorProductVersions
StarletteStarlette framework, including projects and frameworks relying on Starlette

Timeline

  • Sep 27, 2022 CrowdSec Sighting
  • Dec 17, 2022 CrowdSec Sighting
  • Mar 9, 2023 CrowdSec Sighting
  • Apr 5, 2023 CrowdSec Sighting
  • Aug 10, 2023 CrowdSec Sighting
  • Jan 5, 2025 CrowdSec Sighting
  • May 3, 2025 CrowdSec Sighting
  • Jun 28, 2025 CrowdSec Sighting
  • Sep 23, 2025 CrowdSec Sighting
  • Apr 9, 2026 CrowdSec Sighting
  • May 17, 2026 CrowdSec Sighting
  • May 22, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›