BadHost Vulnerability Exposes Sensitive AI Agent Server Endpoints to Attackers
ID: d92c7159-b2f6-5d39-a58f-79f6644772af
STIX ID: report--d92c7159-b2f6-5d39-a58f-79f6644772af
Feed Name: GBHackers
**Executive Summary:** BadHost (CVE-2026-48710) is a critical Host header handling vulnerability in the Starlette framework that lets unauthenticated attackers manipulate request.url to bypass path-based access controls, exposing FastAPI-based AI services and inference servers (vLLM, LiteLLM, MCP servers, OpenAI-compatible APIs) to unauthorized access; organizations are advised to upgrade to Starlette 1.0.1+, validate Host headers at application and proxy layers, and adopt stronger, layered authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
