Risky Bulletin Newsletter
May 27, 2026
Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
Presented by
News Editor
A major bug has been disclosed in a little known middleware component used in many AI server infrastructure products.
Codenamed BadHost (and tracked as CVE-2026-48710), the vulnerability impacts Starlette, a lightweight Python framework for building asynchronous web services.
In the simplest way to explain it, the bug can allow attackers to trick servers into thinking they want to access a public URL and there's no need to authenticate. In reality, the attackers get connected to private endpoints from where they can download or harvest sensitive data or tell the server to perform malicious actions.