A critical authentication bypass vulnerability (CVE-2026-48710) affects Starlette, a popular Python web framework. The flaw allows attackers to bypass host-header validation through crafted requests.
BadHost researchers disclosed CVE-2026-48710, impacting Starlette's host-header authentication mechanisms. The vulnerability stems from insufficient validation of Host headers, enabling attackers to forge requests that pass security checks designed to restrict access to specific domains.
The flaw affects applications relying on Starlette's host-header validation for authentication and authorization decisions. Attackers exploiting this issue could bypass access controls, potentially gaining unauthorized access to protected resources or performing actions on behalf of legitimate users.
Starlette maintainers have been notified and patches are expected. Users running affected versions should prioritize updates once available. As a temporary mitigation, administrators can implement additional host validation at the application or reverse-proxy level.
The vulnerability highlights risks in delegating security decisions to host-header values, which remain inherently spoofable without proper cryptographic verification. Organizations using Starlette should review their authentication implementations and host-validation strategies.
An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.
Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.
Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.
Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.