CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization
CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization Vulnerability overview CVE-2026-48710, tracked publicly as BadHost and catalogued by X41 D-Sec as X41-2026-002, is an authentication bypass in the Starlette ASGI framework. The flaw is CWE-444, inconsistent interpretation of HTTP requests. Starlette maintainers published a GitHub security advisory with a…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.