
Security·
One bad Host header bypassed auth in Starlette, the routing core under millions of AI agents
A flaw in Starlette, downloaded 325M times a week, let a single Host-header character bypass path-based auth across FastAPI, vLLM, and MCP servers.