Dossier
host-header authentication bypass
Coverage of host-header authentication bypass in the Nexus archive.
- BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
A security vulnerability (CVE-2026-48710) in the Starlette Python web framework allows attackers to bypass host-header authentication, as reported by Ars Technica. The flaw could enable unauthorized access to web applications using Starlette, with discussions ongoing on Hacker News.