BadHost Vulnerability Exposes AI Agents, Evaluators, and LLM Gateways
BadHost (CVE-2026-48710) is a high-severity authentication bypass in Starlette (325M weekly downloads), exploiting malformed Host headers to bypass path-based access controls—discovered during a vLLM audit. The vulnerability directly compromises AI agents, LLM gateways, and MCP servers, with exploit chains leading to SSRF and remote code execution, and is argued to be critical rather than moderate given its downstream impact. Many AI services on internal networks lack reverse-proxy protection, making them directly exploitable, while the flaw was missed by AI code analysis tools.