<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #cve-2026-48710</title><description>Articles tagged cve-2026-48710 on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>One bad Host header bypassed auth in Starlette, the routing core under millions of AI agents</title><link>https://devtake.dev/article/ai-agents-package-rce-vulnerability/</link><guid isPermaLink="true">https://devtake.dev/article/ai-agents-package-rce-vulnerability/</guid><description>A flaw in Starlette, downloaded 325M times a week, let a single Host-header character bypass path-based auth across FastAPI, vLLM, and MCP servers.</description><pubDate>Mon, 08 Jun 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>ai-agents</category><category>mcp</category><category>cve-2026-48710</category><category>python</category><category>fastapi</category><author>luca-reinhardt</author></item></channel></rss>