Skip to content
The Nexus
DossierENTITY

host-header authentication bypass

Coverage of host-header authentication bypass in the Nexus archive.

Earliest in view: May 26 · 09:07 UTCMost recent: May 26 · 09:07 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYMay 26 · 09:07 UTCHACKER NEWS
    BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass

    A security vulnerability (CVE-2026-48710) in the Starlette Python web framework allows attackers to bypass host-header authentication, as reported by Ars Technica. The flaw could enable unauthorized access to web applications using Starlette, with discussions ongoing on Hacker News.