Post #4490380
2026-05-22 10:25 UTC
Patch Starlette now! If you're run it via uvicorn or other common ASGI servers then a host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory:
https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/
Replies (0)
No replies.