As cited
Copy frozen at (site build).
vulnerabilities
Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
A vulnerability tracked as CVE-2026-48710 in Starlette, a Python web framework used in AI infrastructure, allows attackers to bypass authentication checks by manipulating URL handling. Exploiting the flaw enables unauthorized access to private endpoints where attackers could exfiltrate sensitive data or execute malicious commands.
Why it matters: This authentication bypass affects AI infrastructure widely; assess your Starlette deployments and apply patches immediately if exposed to untrusted networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
Researchers disclosed a vulnerability named BadHost (CVE-2026-48710) in the Starlette Python framework, a middleware component used in artificial intelligence server infrastructure. The flaw enables unauthenticated access to private endpoints by tricking servers into treating requests as public, potentially exposing sensitive data or allowing malicious commands. Starlette is a lightweight asynchronous web services framework commonly integrated into AI systems.
Why it matters: Organizations using Starlette in AI infrastructure should patch immediately to prevent unauthorized access to private endpoints and data exfiltration.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
CVE-2026-48710, a vulnerability in Starlette middleware used across artificial intelligence (AI) infrastructure, allows attackers to bypass authentication by making servers treat private endpoints as publicly accessible. Exploited this way, attackers can access sensitive data or execute malicious actions on affected systems. The flaw has been assigned a CVSS score of 6.5 and added to the Known Exploited Vulnerabilities catalog.
Why it matters: Organizations running Starlette-based AI server infrastructure face direct risk of unauthorized access to private data and remote code execution; patching should be prioritized given active exploitation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
CVE-2026-48710, a vulnerability in Starlette middleware used across artificial intelligence (AI) infrastructure, allows attackers to bypass authentication by making servers treat private endpoints as publicly accessible. Exploited this way, attackers can access sensitive data or execute malicious actions on affected systems. The flaw has been assigned a CVSS score of 6.5 and added to the Known Exploited Vulnerabilities catalog.
Why it matters: Organizations running Starlette-based AI server infrastructure face direct risk of unauthorized access to private data and remote code execution; patching should be prioritized given active exploitation.
- Source published
- First seen by Cybersecurity Tracker