BadHost Vulnerability Exposes AI Agents, Evaluators, and LLM Gateways
325M weekly downloads. One authentication bypass just exposed AI agent infrastructure across the industry.

Why it matters
A critical vulnerability in Starlette—a foundational web framework for AI systems—creates an immediate security risk for companies deploying AI agents and LLM gateways. This is the kind of systemic infrastructure weakness that forces CTOs to audit their entire stack.
The key facts
6 to knowBadHost vulnerability in Starlette framework
325 million weekly downloads of affected framework
High-severity authentication bypass via malformed HTTP Host headers
Impacts AI agent infrastructure, LLM gateways, and evaluators
Path-based access control bypass
Published June 1, 2026
Go to the source
InfoQ AI/MLinfoq.com
Publisher excerpt: BadHost is a high-severity authentication bypass vulnerability in the widely used Python web framework Starlette, with 325 million weekly downloads. The flaw allows attackers to use malformed HTTP Host headers to bypass path-based access controls and access sensitive AI agent infrastructure, among…