Starlette host-header vulnerability exposes auth bypass risk
Hacker News·2h·ylk
A critical CVE in Starlette's host validation lets attackers bypass authentication by manipulating the Host header—a common pitfall in web frameworks. If you're using Starlette for any auth-sensitive work, this is worth reviewing immediately, especially if you rely on host-based routing or checks.
Original story
Read the original on Hacker NewsRelated stories
AI
Moltnet: self-hostable chat network built for agent-to-agent communicationHacker News Show HN·9m·apresmoi

Open source
Rare IBM System/360 archival footage surfaces on storage architectureHacker News·9m·DaiPlusPlus

AI
Mneme HQ lets you codify architectural rules directly in your repo for AI coding agentsHacker News Show HN·9m·Tval
AI
Claude Usage Tray puts Claude Code rate-limit status in your Windows system trayHacker News Show HN·9m·JosephZeng