build1 distinct publisher
A query string smuggled into the Host header makes Starlette skip authentication
X41 D-Sec's proof of concept for CVE-2026-48710 is one unauthenticated GET whose Host header carries /public?bar=. Starlette sits underneath LiteLLM, vLLM and MCP servers, so the work starts with a dependency query.
Publishers:news.risky.biz
Reality
- Evidence56
- Adoption
- Insufficient
- Hype gap+18
- Incentives55