High · CVSS Pending May 26, 2026 · X41 D-Sec / OSTIF / Persistent Security

BadHost: Starlette Host-Header Auth Bypass

How a host-header parsing flaw reaches AI agent infrastructure

Starlette before 1.0.1 reconstructed request.url from the untrusted Host header without validation, allowing request.url.path to diverge from the actual HTTP request path. Middleware that trusted the reconstructed value could be bypassed by sending a crafted Host header — granting unauthenticated access to protected endpoints in FastAPI applications, MCP servers, LLM proxies, and AI agent backends. Fixed in Starlette 1.0.1, which validates the Host header and falls back to ASGI scope data for malformed values.

1 CVE
Pending CVSS Score
CWE-444 Class
Remote Access Required

Technical Breakdown

CVE-2026-48710 High · CVSS Pending Auth Middleware Bypass

BadHost — Starlette Host-Header Authentication Bypass

Starlette before 1.0.1 reconstructed request.url from the untrusted Host header without validation. This caused request.url.path to diverge from the actual HTTP request path in the ASGI scope. Middleware that trusted the reconstructed value for authorization decisions could be bypassed by sending a crafted Host header such as example.com/health?x=, causing the middleware to evaluate an allowed path while the actual request targets a protected route. Affected: Starlette < 1.0.1.

CWE: CWE-444 — Inconsistent Interpretation of HTTP Requests  |  Fixed in: Starlette 1.0.1  |  Workaround: Replace request.url.path with scope['path'] in all middleware

Root Cause

ASGI frameworks expose two ways to read the current request path: scope['path'], which comes from the raw HTTP request line and is authoritative, and request.url.path, which Starlette reconstructed by parsing the Host header. Because Host is attacker-controlled, these two values can be made to disagree. Middleware that used the reconstructed value was checking attacker-supplied data.

Vulnerable Pattern

Any BaseHTTPMiddleware or raw ASGI middleware that reads request.url.path for authorization. FastAPI route handlers using Depends() or Security() are not affected because they operate on the actual matched route, not the reconstructed URL. The vulnerability only affects middleware-layer authorization.

Why AI Services Are High-Value

MCP servers hold credentials to databases, email, calendars, SaaS systems, and external tools used by agents. LLM gateways store provider API keys for every tenant and model. Agent orchestration services hold tool credentials and workflow state. A middleware bypass gives attackers access to these credential stores without any authentication.

The Fix

Starlette 1.0.1 validates the Host header and falls back to ASGI scope data for malformed values, eliminating the divergence. Additionally, replacing any remaining request.url.path usage in middleware with scope['path'] removes the root cause entirely regardless of framework version.

Attack Chain

1

Identify an Exposed ASGI Service

Attacker identifies a FastAPI, Starlette, MCP server, LLM proxy, or agent backend that exposes an ASGI server and uses custom path-based middleware for authentication. These services are often accessible on internal networks or, in misconfigured environments, the public internet — and their middleware-protected endpoints are typically well-documented in API specs or discoverable through error responses.

Maintain an up-to-date inventory of all ASGI-based services. Restrict external exposure behind RFC-compliant reverse proxies that normalize host headers before they reach the ASGI layer.

2

Confirm Path-Based Middleware Authorization

Attacker confirms that unauthenticated requests to a protected endpoint are rejected with a 401 or 403, establishing that access control is implemented in middleware reading request.url.path. Unauthenticated access to a known-public path (such as /health) confirms the middleware pattern and establishes the allowed-path allowlist.

Audit all middleware for authorization logic that reads request.url.path. Replace with endpoint-level Depends() or Security() patterns that operate on actual route state.

3

Craft a Malformed Host Header

Attacker sends a crafted Host value such as example.com/health?x= while targeting a protected route in the actual HTTP request line (e.g. GET /admin/keys HTTP/1.1). Starlette's URL reconstruction causes request.url.path to evaluate as /health — an allowed route — while the actual ASGI scope['path'] remains /admin/keys.

Upgrade to Starlette ≥ 1.0.1. Place services behind nginx, Caddy, Traefik, or HAProxy to normalize host headers before they reach the ASGI layer — this mitigates an entire class of host-header attacks regardless of framework version.

4

Bypass Authentication Middleware

The middleware evaluates request.url.path as an allowed route and passes the request through to the protected handler without requiring authentication. The handler executes normally — returning credentials, model API responses, agent state, or whatever the protected endpoint exposes — delivering full unauthenticated access to the target resource.

Use scope['path'] instead of request.url.path in any remaining middleware. The ASGI scope path derives from the HTTP request line and cannot be manipulated via the Host header.

Impact

BadHost is a reminder that agentic systems amplify ordinary web bugs. Compromised AI service gateways become credential-rich control planes — a single middleware bypass propagates across every agent, model, and downstream system that trusts the affected service.

MCP Servers

  • Credentials to databases, email, and calendars used by agents
  • SaaS system tokens (CRM, Slack, Google Workspace)
  • External tool API keys exposed to attacker
  • Full agent action surface accessible without authentication

LLM Inference & Proxy Services

  • Model provider API keys (OpenAI, Anthropic, etc.)
  • Tool credentials and agent workflow state
  • Billing fraud via unauthorized model usage
  • Prompt history and inference outputs exposed

Affected Sectors

  • Biopharma AI data pipelines
  • Identity verification and IoT/ICS access systems
  • HR, recruitment, and document management platforms
  • Cloud monitoring, health, and finance AI services

Defensive Tutorial

IMMEDIATE · 0–24 HRS

Inventory all ASGI-based AI services

Immediate

Find every FastAPI, Starlette, vLLM, LiteLLM, MCP gateway, agent backend, and custom AI service in your environment that may include Starlette as a direct or transitive dependency. Check pip show starlette in each service's environment and inspect requirements.txt / pyproject.toml lock files. Any version below 1.0.1 is affected.

IMMEDIATE · 0–24 HRS

Upgrade Starlette to ≥ 1.0.1

Immediate

Run pip install --upgrade starlette in each affected environment, or update the version pin and redeploy. For FastAPI applications, upgrading FastAPI to a version that pulls in Starlette 1.0.1+ is sufficient. Verify the installed version before re-enabling external traffic. This is the only complete fix.

IMMEDIATE · 0–24 HRS

Audit middleware for request.url.path usage

Immediate

Grep your codebase for request.url.path in BaseHTTPMiddleware or raw ASGI middleware. Treat every match as a required review item. Replace authorization logic that uses request.url.path with scope['path'], or move the authorization to endpoint-level Depends() / Security() patterns.

SHORT-TERM · 1–7 DAYS

Place all ASGI services behind a reverse proxy

Important

Deploy nginx, Caddy, Traefik, or HAProxy in front of every ASGI service. Configure the proxy to normalize and validate Host headers before forwarding requests. This is a durable architectural control that mitigates the entire class of host-header attacks regardless of Starlette version — and prevents a range of other HTTP request smuggling and header injection vulnerabilities.

SHORT-TERM · 1–7 DAYS

Move authorization to endpoint-level security

Important

Use Starlette's @requires() decorator or FastAPI's Depends() and Security() patterns for all authorization logic. These are enforced against the actual route handler and cannot be bypassed by a manipulated URL — they derive route state from the ASGI routing machinery, not from the reconstructed URL string.

SHORT-TERM · 1–7 DAYS

Verify exposure with the BadHost scanner

Important

Use the BadHost scanner or a controlled proof-of-concept against systems you own or are authorized to test. Confirm that protected endpoints return 401/403 responses regardless of Host header value. Restrict all testing to authorized targets only. Document results as evidence for your remediation audit trail.

LONG-TERM

Establish dependency SBOMs for AI platforms

Important

Maintain a software bill-of-materials for all AI gateways, agent orchestration layers, and MCP servers — including transitive dependencies. Set framework upgrade SLOs (e.g. 30-day window for high-severity patches) and include HTTP parser differential tests in pre-production security validation pipelines. AI infrastructure is web-framework infrastructure; treat it accordingly.

References

  • NVD CVE-2026-48710 — Starlette Host-Header Auth Bypass · NIST National Vulnerability Database, May 26, 2026
  • Original Research BadHost Advisory — X41 D-Sec, OSTIF, Persistent Security, 2026
  • CWE Reference CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
  • Background Millions of AI agents imperiled by critical vulnerability in open source package — external reporting on AI agent ecosystem exposure
Advisory analysis by Spectreworks AI. Original research by X41 D-Sec, OSTIF, and Persistent Security. All defensive recommendations are based on publicly available disclosure information. Verify patch applicability against your specific deployment before production changes.