CVE-2026-48710
Starlette Host Header Validation Bypass Vulnerability
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A vulnerability in the Starlette web framework allows attackers to bypass security measures by sending malformed HTTP `Host` headers. This could lead to the improper reconstruction of request URLs, potentially enabling unauthorized access if security relies on these reconstructed paths. Readers should care because this