logo

BadHost Vulnerability Exposes Sensitive AI Agent Server Endpoints to Attackers

ID: d92c7159-b2f6-5d39-a58f-79f6644772af

STIX ID: report--d92c7159-b2f6-5d39-a58f-79f6644772af

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Divya

...
...

**Executive Summary:** BadHost (CVE-2026-48710) is a critical Host header handling vulnerability in the Starlette framework that lets unauthenticated attackers manipulate request.url to bypass path-based access controls, exposing FastAPI-based AI services and inference servers (vLLM, LiteLLM, MCP servers, OpenAI-compatible APIs) to unauthorized access; organizations are advised to upgrade to Starlette 1.0.1+, validate Host headers at application and proxy layers, and adopt stronger, layered authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.