Worrying open source ‘BadHost’ security issue could affect millions of AI agents, experts warn


  • Secwest discloses CVE‑2026‑48710 (“BadHost”), a high severity flaw in Starlette that allows attackers to abuse malformed Host headers to bypass security controls and exfiltrate sensitive data.
  • Starlette supports frameworks like FastAPI and is widely deployed; researchers warn that the score of 7/10 underestimates the risk, with data from AI agents, biopharmaceuticals, IoT and SaaS potentially exposed.
  • The bug was fixed in version 1.0.1, but vulnerable versions remain common in production, making immediate upgrades and environmental scans critical.

A lightweight Python web framework called Starlette contained a high-severity vulnerability that could allow malicious actors to exfiltrate sensitive data from millions of AI agents, experts have warned.

Some researchers even suggest that current descriptions of the fault don’t do it justice, as it is one of the largest and potentially most disruptive faults in recent times.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top