CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 183

As cited

Copy frozen at (site build).

vulnerabilities

Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

A vulnerability tracked as CVE-2026-48710 in Starlette, a Python web framework used in AI infrastructure, allows attackers to bypass authentication checks by manipulating URL handling. Exploiting the flaw enables unauthorized access to private endpoints where attackers could exfiltrate sensitive data or execute malicious commands.

Why it matters: This authentication bypass affects AI infrastructure widely; assess your Starlette deployments and apply patches immediately if exposed to untrusted networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

Researchers disclosed a vulnerability named BadHost (CVE-2026-48710) in the Starlette Python framework, a middleware component used in artificial intelligence server infrastructure. The flaw enables unauthenticated access to private endpoints by tricking servers into treating requests as public, potentially exposing sensitive data or allowing malicious commands. Starlette is a lightweight asynchronous web services framework commonly integrated into AI systems.

Why it matters: Organizations using Starlette in AI infrastructure should patch immediately to prevent unauthorized access to private endpoints and data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

CVE-2026-48710, a vulnerability in Starlette middleware used across artificial intelligence (AI) infrastructure, allows attackers to bypass authentication by making servers treat private endpoints as publicly accessible. Exploited this way, attackers can access sensitive data or execute malicious actions on affected systems. The flaw has been assigned a CVSS score of 6.5 and added to the Known Exploited Vulnerabilities catalog.

Why it matters: Organizations running Starlette-based AI server infrastructure face direct risk of unauthorized access to private data and remote code execution; patching should be prioritized given active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

CVE-2026-48710, a vulnerability in Starlette middleware used across artificial intelligence (AI) infrastructure, allows attackers to bypass authentication by making servers treat private endpoints as publicly accessible. Exploited this way, attackers can access sensitive data or execute malicious actions on affected systems. The flaw has been assigned a CVSS score of 6.5 and added to the Known Exploited Vulnerabilities catalog.

Why it matters: Organizations running Starlette-based AI server infrastructure face direct risk of unauthorized access to private data and remote code execution; patching should be prioritized given active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary