Starlette is a technology platform tracked across 3 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed May 26, 2026; most recent activity June 9, 2026.
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
A severe vulnerability known as BadHost (CVE-2026-48710) has been identified in the Starlette framework, affecting millions of AI applications, including those built on FastAPI. This flaw allows unauthenticated…
A vulnerability in Starlette, a Python ASGI framework, allows attackers to manipulate the Host header, leading to potential authentication bypass and other security issues. The flaw arises from Starlette's failure to…