Back Gigazine A vulnerability in the open-source package 'Starlette,' which is downloaded more than 300 ...
Security researcher Markus Vervier warns that Starlette , an open-source framework used by millions of AI agents and tools worldwide, has a critical vulnerability. Millions of AI agents imperiled by critical vulnerability in open source package - Ars Technica
Security firm X41 D-Sec, which discovered BadHost, states that 'simply inserting a single character into the HTTP
X41 D-Sec pointed out that BadHost 'Starlette's routing algorithm relies on the HTTP path, but the request.url.path attribute provided to middleware and endpoints is based on the reconstructed URL. It is unexpected for the user when request.url.path differs from the path actually requested over HTTP.' Because vulnerable versions of Starlette are still widely used on production systems, users with applications that rely on Starlette (especially FastLLM, vLLM, and LiteLLM) should at least run a scanner on their systems to detect if any vulnerable code is still being used.
May 27, 2026 11:04:00 in AI , Software , Security , Posted by logu_ii
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
