Self-Hosting
BadHost in My Own Rack: Auditing a Self-Hosted AI Stack for the Starlette Host-Header Bypass
I audited my self-hosted AI stack against CVE-2026-48710 (BadHost), the Starlette host-header auth bypass. One component ran an affected version and stayed protected by code, not by patch. The exact per-container checks, and the scan that exposed it.