BadHost – CVE-2026-48710 Starlette Host-Header Auth Bypass

ylk 14 points 3 comments May 26, 2026
mcp-scan.nemesis.services · View on Hacker News

Discussion Highlights (2 comments)

ylk

The URL was meant to be https://badhost.org , the site accidentally still has the old canonical meta tag.

ostif-derek

This is a bad one. Rating it a medium understates how hard it hits thousands of downstream projects and billions of installs. People need to patch asap. I'm normally against the "giving a bug a name, logo, and website" trope, but this one is getting poor patch rates because of it being rated a medium and landing right before a big American holiday weekend.

Semantic search powered by Rivestack pgvector
8,541 stories · 80,649 chunks indexed