A Host-Header Bug in Starlette Affects Every FastAPI App Built On It
CVE-2026-48710, a moderate-severity Host-header validation gap in the Starlette framework underlying FastAPI, was still confirmed exploited — CVSS is not the only signal that matters.