---
reference_key: ostif-badhost
title: "OSTIF --- BadHost vulnerability in Starlette"
url: "https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/"
availability: available
capture_method: primary
captured_at: 2026-06-23T03:31:14Z
document_id: REF-ostif-badhost
---

# OSTIF --- BadHost vulnerability in Starlette

| Field | Value |
|-------|-------|
| **Reference key** | `ostif-badhost` |
| **Availability** | AVAILABLE |
| **Capture method** | `primary` |
| **Source type** | remote_url |
| **URL / path** | https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/ |
| **Captured (UTC)** | 2026-06-23T03:31:14Z |
| **Content type** | text/html; charset=UTF-8 |
| **HTTP status** | 200 |

## Boardroom Citation Context

P7-11b Starlette >=1.0.1 requirement.

## Source Location

https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/





## Captured Content

```text
Disclosing the BADHOST Vulnerability in Starlette  OSTIF.org Skip to content Get an Audit Sponsor Us About Us Audits Community News Toggle website search Get an Audit Sponsor Us About Us Audits Community News Toggle website search Disclosing the BADHOST Vulnerability in Starlette Post published: May 26, 2026 Post category: AWS / News / Open Source / X41-Dsec BAD HOST OSTIF is disclosing the expanded details of the BadHost vulnerability in Starlette as slow uptake of updated versions of Starlette and discovery of more vulnerable live services has caused us serious concerns. Id like to open by saying that the maintainer of Starlette is having a bad few weeks. This disclosure + patch process has been long and a lot of parties have been contacting them about this while they are simultaneously dealing with a large pile of other security reports that every open source project is dealing with in 2026. This bug is a classic responsibility gap where if this maintainer didnt patch, thousands of exposed projects would have to individually secure their projects. In doing this work, theyve voluntarily taken on the responsibility to protect the ecosystem from long-term systemic harm. As with all open source projects, they owed us nothing and could have left this to be everyone elses problem and took the extraordinary steps of helping the ecosystem. Please consider donating to Kludex: https://github.com/sponsors/Kludex What is BadHost? https://www.secwest.net/starlette A lack of input sanitization on host header paths in Starlette leads to bypassing auth with a single character across a huge swath of Python LLM infrastructure. This hits very large and prominent projects such as FastAPI, LiteLLM, vLLM, text generation inference projects, most OpenAI shim proxies, MCP servers, Agent harnesses, eval dashboards and model-management UIs. Identified as CVE-2026-48710 information is still propagating about this bug. https://security-tracker.debian.org/tracker/CVE-2026-48710 https://osv.dev/vulnerability/DEBIAN-CVE-2026-48710 https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr (rating severely understates the severity of the bug downstream) Starlette reconstructs request.url by concatenating the HTTP Host header with the request path and re-parsing the result. The Host value is not validated against the RFC 9112 / RFC 3986 grammar before reconstruction. A Host header containing /, ?, or # shifts the path, query, and fragment boundaries during re-parse, so request.url.path no longer matches the path the ASGI server actually received and routed against. The router dispatches on the real wire path. Middleware sees the poisoned, re-parsed path. Any path-based security decision made in middleware can be bypassed while the underlying route still executes. How bad is this? A minimal POC: curl -i -H Host: foo http://target/admin # 403, blocked curl -i -H Host: foo? http://target/admin # 200, served Where Starlette-based middleware (including FastAPI middleware) enforces authorization or routing restrictions using request.url or request.url.path, the following should be assumed reachable by an unauthenticated remote attacker: Bypass of path-prefix authentication (/admin, /v1/models, /internal, /metrics, /shutdown, tool-execution endpoints) Bypass of tenant or workspace scoping enforced in middleware Smuggling of requests into endpoints intended to be reachable only from authenticated sessions or internal hops SSRF against cloud metadata services and internal hosts where the gated endpoint performs outbound fetches RCE where the gated endpoint exposes tool execution, plugin loading, arbitrary model loading from URL, file upload, or code-eval style functionality For LLM gateways specifically, the admin and key-management surface of services like LiteLLM, and the model and runtime control surface of services like vLLM, must be treated as exposed if the deployment is direct-to-ASGI. How widespread is this? This affects vLLM, LiteLLM, and FastAPI and many many more. These projects collectively make up the vast majority of all Python LLM infrastructure today. Test for this Vulnerability BadHost.org has tooling to examine your infrastructure and determine if it is vulnerable. The BadHost project, run jointly by X41 D-Sec, Persistent Security Industries, and Bintech, offers a free remote scanner for any reachable HTTP endpoint at badhost.org. Suitable for quick triage of a few services. X41 has also published a scanner, Semgrep rules, and CodeQL queries at Github.com/x41sec/poc/tree/master/starlette-host-header . Run these across any Python codebase that touches Starlette or FastAPI to find affected middleware patterns. The repository also includes a runtime PoC for confirming exposure on a deployed instance. If you dont want to use tooling, you are likely exposed if ANY of the following are true: You run any FastAPI or Starlette application directly on uvicorn, hypercorn, daphne, or granian without an HTTP/1.1-compliant reverse proxy in front. You run LiteLLM, vLLM, or similar LLM proxies and servers as the directly-reachable HTTP endpoint. You terminate HTTP/3 or QUIC at a frontend whose Host validation behavior you have not verified. Your application reads request.url.path in any authentication, authorization, audit, rate-limiting, or routing-decision code. Any internal-only service is reachable from a workstation, VPN subnet, lab network, or other we trust this network segment. Mitigation Update to Starlette 1.0.1 as soon as possible . Rebuild and redeploy every container, virtualenv, and bundled artifact that pins or vendors Starlette. Bundled installs are common in LLM tooling; pip list on the host is not enough. Audit images. OR Replace request.url and request.url.path with request.scope[path] in every middleware, dependency, and decorator that makes security decisions. Grep the codebase. This bug class will recur; reading the un-reconstructed value is the durable fix. Place a reverse proxy that rejects malformed Host headers in front of every ASGI-served application. nginx, Apache httpd, and Cloudflare reject the PoC by default. Verify your specific config. For HTTP/3-terminated frontends, test Host header handling explicitly with the X41 PoC before relying on the proxy as a mitigation. This bug was discovered through manual analysis by a senior security expert at X41 D-Sec during a security audit of vLLM managed by OSTIF.org that was sponsored by the Alpha-Omega Project . Our continued efforts to analyze downstream affected projects and notify everyone exposed was sponsored in part by Amazon Web Services . Tags : ASGI , Audit , badhost , Starlette , vllm , x41 , x41 D-Sec Topics 7ASecurity ADA Logics Audits AWS Bug Bounties Chainguard CNCF Community Eclipse Foundation Encryption Financial Fundraiser Include Security Kudelski Security Linux Kernel Monero News Open Source OpenSSL OpenVPN QuarksLab Security Shielder Sovereign Tech Agency Sovereign Tech Agency Trail of Bits Transparency Unbound DNS Uncategorized VeraCrypt WireGuard X41-Dsec Archives Archives Select Month June 2026 May 2026 April 2026 March 2026 February 2026 January 2026 December 2025 November 2025 October 2025 September 2025 August 2025 July 2025 June 2025 May 2025 April 2025 March 2025 February 2025 January 2025 December 2024 October 2024 September 2024 August 2024 July 2024 June 2024 May 2024 April 2024 March 2024 February 2024 January 2024 December 2023 November 2023 October 2023 September 2023 August 2023 July 2023 June 2023 May 2023 April 2023 March 2023 February 2023 January 2023 December 2022 November 2022 October 2022 August 2022 July 2022 June 2022 November 2021 October 2021 September 2021 June 2021 January 2021 July 2020 April 2020 December 2019 August 2019 July 2019 June 2019 May 2019 February 2019 January 2019 October 2018 September 2018 July 2018 May 2018 March 2018 January 2018 November 2017 October 2017 September 2017 July 2017 June 2017 May 2017 April 2017 March 2017 February 2017 January 2017 December 2016 November 2016 October 2016 September 2016 August 2016 June 2016 May 2016 April 2016 February 2016 January 2016 December 2015 November 2015 October 2015 September 2015 July 2015 May 2015 Categories 7ASecurity ADA Logics Audits AWS Bug Bounties Chainguard CNCF Community Eclipse Foundation Encryption Financial Fundraiser Include Security Kudelski Security Linux Kernel Monero News Open Source OpenSSL OpenVPN QuarksLab Security Shielder Sovereign Tech Agency Sovereign Tech Agency Trail of Bits Transparency Unbound DNS Uncategorized VeraCrypt WireGuard X41-Dsec Archives June 2026 May 2026 April 2026 March 2026 February 2026 January 2026 December 2025 November 2025 October 2025 September 2025 August 2025 July 2025 June 2025 May 2025 April 2025 March 2025 February 2025 January 2025 December 2024 October 2024 September 2024 August 2024 July 2024 June 2024 May 2024 April 2024 March 2024 February 2024 January 2024 December 2023 November 2023 October 2023 September 2023 August 2023 July 2023 June 2023 May 2023 April 2023 March 2023 February 2023 January 2023 December 2022 November 2022 October 2022 August 2022 July 2022 June 2022 November 2021 October 2021 September 2021 June 2021 January 2021 July 2020 April 2020 December 2019 August 2019 July 2019 June 2019 May 2019 February 2019 January 2019 October 2018 September 2018 July 2018 May 2018 March 2018 January 2018 November 2017 October 2017 September 2017 July 2017 June 2017 May 2017 April 2017 March 2017 February 2017 January 2017 December 2016 November 2016 October 2016 September 2016 August 2016 June 2016 May 2016 April 2016 February 2016 January 2016 December 2015 November 2015 October 2015 September 2015 July 2015 May 2015 TALK TO OSTIF Bluesky LinkedIn Mastodon Youtube Github Copyright  2025 Open Source Technology Improvement Fund. All rights reserved.
```

---

*Archived reference article for AICSR-STUDY-2026-001 footnote corpus.*
