Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability called BadHost that can allow hackers to bypass authorization Ars Technica 2026-05-28 Dan Goodin BadHost, Python, Starlette Related Coverage Request Host Header not Validated in Starlette X41 D-Sec FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework CSO · Gyana Swain BadHost - CVE-2026-48710: Starlette Host-Header Auth Bypass Hacker News Millions of AI agents imperiled by critical vulnerability in open source package Ars OpenForum Discussion @eve.gd Martin Paul Eve on bluesky This is dire. Starlet is the core of FastAPI and many other Python implementations of web/API servers. The compromise here will be extremely widespread and difficult to contain. — arstechnica.com/information- ... r/LocalLLaMA r on reddit Vulnerability found in framework used by VLLM, many MCP servers, and other LLM tools r/technology r on reddit Millions of AI agents imperiled by critical vulnerability in open source package