#web-request-validation

[ follow ]
Information security
fromInfoWorld
2 days ago

FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework

A malformed Host header can bypass Starlette host-validation, letting unauthenticated attackers evade access controls across LLM gateways, MCP servers, and agent infrastructure.
[ Load more ]