Millions of AI agents imperiled by critical vulnerability in open source package
… BadHost affects Starlette versions prior to 1.0.1, which was released Friday. “A single character injected into the HTTP Host header bypasses path-based authorization in Starlette, the routing core of FastAPI,” researchers from Secwest wrote. “Through FastAPI, this primitive now tracked as CVE-2026… …