← العودة للجدول
CVE-2026-48710
FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
📅 2026-05-27 17:46:10
🔴 Critical 🔥 No CSO Online AI Attack Exploit 🎯 EPSS 0.03%

📋 الوصف الكامل

A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said. The flaw, tracked as CVE-2026-48710 could allow attackers to bypass host-validation protections using malformed Host headers, according to an advi

💻 الأنظمة المتأثرة

FastAPI-based AI tools

⚠️ نوع التهديد

AI Attack

🔗 CVE ID

CVE-2026-48710

📡 المصدر

CSO Online

✅ الحلول والتخفيف

Refer to CVE-2026-48710 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←