Critical BadHost vulnerability in Starlette framework lets hackers bypass authentication on millions of AI agents, threatening sensitive data and credentials.

BadHost" was found in Starlette, a package with 325 million weekly downloads.

Critical BadHost vulnerability in Starlette framework lets hackers bypass authentication on millions of AI agents, threatening sensitive data and credentials.

Researchers who found the bug warn that its Moderate rating understates a threat reaching across LLM gateways, MCP servers and agent infrastructure.