Vendor
CVE-2026-48710, also known as BadHost, is an authentication bypass vulnerability affecting the Starlette framework before version 1.0.1, and related frameworks like FastAPI, vLLM, and LiteLLM, due to a lack of input sanitization on host header paths, potentially allowing attackers to access sensitive data and steal credentials.