BadHost – CVE-2026-48710 Starlette Host-Header Auth Bypass
A critical vulnerability tracked as CVE-2026-48710 (BadHost) in Starlette versions prior to 1.0.1 allows attackers to bypass path-based authentication middleware by injecting a crafted Host header that manipulates the `r…