---
schema: 1
kind: vulnerability
title: "CVE-2026-48710 \"BadHost\" — Starlette (FastAPI / vLLM / LiteLLM / MCP SDK): Pre-Auth Auth Bypass via Malformed Host Header"
headline: "CVE-2026-48710 \"BadHost\" — Starlette (FastAPI / vLLM / LiteLLM / MCP SDK): Pre-Auth Auth Bypass via Malformed Host Header"
summary: "CVE-2026-48710 \"BadHost\" — Starlette/FastAPI host-header auth bypass hits AI/ML serving infrastructure including vLLM, LiteLLM, and MCP servers (NCSC-NL NCSC-2026-0171, 2026-05-29). A single malformed Host header character shifts request.url.path so middleware grants access to an unintended route. Fix: Starlette ≥ 1.0.1."
discovered_at: "2026-05-30T05:00:05Z"
event_date: 2026-05-22
run_id: 2026-05-30-aca445cc
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - auth-bypass
  - poc-public
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-48710
    cvss: "6.5"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://badhost.org/"
    publisher: X41 D-Sec / badhost.org
    role: primary
  - url: "https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/"
    publisher: OSTIF.org
    role: corroborating
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0171"
    publisher: NCSC-NL NCSC-2026-0171
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Audit FastAPI / vLLM / LiteLLM / MCP server deployments for CVE-2026-48710** — Enumerate Python ASGI processes listening directly on a port without a compliant reverse proxy (nginx, Caddy, Traefik, HAProxy). Direct-listen deployments using path-based access control are fully exposed. Upgrade Starlette to ≥ 1.0.1 via the downstream framework's package (FastAPI ≥ 0.115.5, vLLM ≥ 0.23.0). For Kubernetes, verify ingress controller (nginx-ingress is protective by default). Reference: [X41 D-Sec / badhost.org](https://badhost.org/)."
migrated_from: briefs/2026-05-30.md
---

Starlette < 1.0.1 reconstructs `request.url` by concatenating the HTTP `Host` header with the request path and re-parsing the composite string, but validates each component under separate rules ([X41 D-Sec Advisory x41-2026-002, 2026-05-22](https://badhost.org/); [GitHub Advisory GHSA-86qp-5c8j-p5mr](https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr)). Injecting a `/`, `?`, or `#` into the `Host` header (e.g. `Host: example.com/health?x=`) shifts the path boundary reported by `request.url.path`, causing middleware applying path-based access control to authorise access to an unintended route while the ASGI handler serves the attacker-specified one. A single `curl -H 'Host: foo?' localhost:8000/admin` bypasses authentication. Root cause: CWE-436 (Interpretation Conflict). CVSS 3.1 = 6.5 (GitHub Advisory); X41 scores 7.0 under CVSS 4.0. Affected: all Starlette versions ≥ 0.8.3, < 1.0.1; downstream dependents include FastAPI, vLLM, LiteLLM, Google ADK-Python, BentoML, Gradio, Langflow, Open WebUI, and the Python MCP SDK — approximately 325 million weekly downloads and 400,000+ GitHub dependents. Discovered by X41 D-Sec during an OSTIF-sponsored vLLM audit. Nginx, Apache, Caddy, Traefik, HAProxy, and Cloudflare all terminate malformed Host headers upstream; only direct-listen Python ASGI deployments without a compliant reverse proxy are exposed. No confirmed exploitation as of publication. NCSC-NL issued advisory NCSC-2026-0171 on 29 May; CCB Belgium issued a "Patch Immediately" advisory. Fix: upgrade Starlette to ≥ 1.0.1 (or pull FastAPI ≥ 0.115.5, vLLM ≥ 0.23.0, or the equivalent downstream package that pins the fixed Starlette). If patching is not immediately possible, place a compliant reverse proxy in front of any ASGI application using path-based access control. Detection: parse web-server access logs for Host header values containing `/`, `?`, or `#` followed by path components.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-0257 | Palo Alto PAN-OS GlobalProtect | 7.8 (CVSS 4.0) | — | Yes (2026-05-29) | Yes — ITW waves 2026-05-18, 2026-05-21 | 10.2.7-h34+, 11.1.4-h33+, 11.2.4-h17+, 12.1.4-h6+ | [PAN PSIRT](https://security.paloaltonetworks.com/CVE-2026-0257) |
| CVE-2026-48710 | Starlette / FastAPI / vLLM / LiteLLM / MCP SDK | 6.5 (CVSS 3.1) / 7.0 (CVSS 4.0) | — | No | No confirmed exploitation | Starlette ≥ 1.0.1 | [GitHub Advisory](https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr) |
