Vulnerability Management

High-severity Starlette vulnerability ‘BadHost’ could expose sensitive data

Cybersecurity Alert Critical System Vulnerability Detected

A high-severity vulnerability dubbed "BadHost" has been disclosed in the Starlette Python web framework, potentially allowing attackers to bypass security checks and exfiltrate sensitive data from millions of AI agents, as reported by Tech Radar.

The flaw, tracked as CVE-2026-48710, arises from the framework's handling of malformed Host headers. Attackers can exploit this by sending crafted headers that cause Starlette to construct incorrect URLs, leading security measures to inspect the wrong paths. While patched in version 1.0.1, researchers warn that vulnerable versions remain widely deployed.

Experts suggest the 7/10 severity score understates the true risk, with potential exposure of data from AI agents, biopharma, IoT, SaaS, and more. Immediate upgrades and environment scans are urged for affected organizations.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds