Dossier
Starlette
Coverage of Starlette in the Nexus archive.
- Millions of AI agents imperiled by critical vulnerability in open source package
A critical vulnerability in the Starlette open-source framework, used by millions of AI agents and tools, allows hackers to breach servers and steal sensitive data. Starlette, with 325 million weekly downloads, underpins frameworks like FastAPI and enables access to external systems via the Model Context Protocol (MCP), making stolen credentials highly valuable.
- BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
A security vulnerability (CVE-2026-48710) in the Starlette Python web framework allows attackers to bypass host-header authentication, as reported by Ars Technica. The flaw could enable unauthorized access to web applications using Starlette, with discussions ongoing on Hacker News.