Skip to content
A vulnerability in the open-source package 'Starlette,' which is downloaded more than 300 ...

A vulnerability in the open-source package 'Starlette,' which is downloaded more than 300 ...

Gigazine May 27, 2026

Security researcher Markus Vervier warns that Starlette , an open-source framework used by millions of AI agents and tools worldwide, has a critical vulnerability. Millions of AI agents imperiled by critical vulnerability in open source package - Ars Technica

Security firm X41 D-Sec, which discovered BadHost, states that 'simply inserting a single character into the HTTP

X41 D-Sec pointed out that BadHost 'Starlette's routing algorithm relies on the HTTP path, but the request.url.path attribute provided to middleware and endpoints is based on the reconstructed URL. It is unexpected for the user when request.url.path differs from the path actually requested over HTTP.' Because vulnerable versions of Starlette are still widely used on production systems, users with applications that rely on Starlette (especially FastLLM, vLLM, and LiteLLM) should at least run a scanner on their systems to detect if any vulnerable code is still being used.

May 27, 2026 11:04:00 in AI , Software , Security , Posted by logu_ii

Extracted Entities

Platforms (1)

Vulnerabilities (1)