BadHost - CVE-2026-48710 Starlette Host-Header Auth Bypass
Free online scanner for CVE-2026-48710 (BadHost): a critical Starlette vulnerability that lets attackers bypass authentication via Host header injection. Affects FastAPI, Starlette, vLLM, LiteLLM, MCP servers, and any Python ASGI app with path-based auth middleware.
CVE-2026-48710 - Nemesis - BadHost ยท X41 D-Sec & Persistent Security Industries & Bintech