Python-Security

2 posts

/badhost-starlette-cve-2026-48710/featured-image.png
BadHost Breaks Into FastAPI and vLLM With a Single Character

May 27, 2026

BadHost is one character in an HTTP header that bypasses authentication on FastAPI, vLLM, LiteLLM, and the Python MCP SDK. They all run on Starlette. Starlette …

/pypi-supply-chain-attack-xinference-teampcp/featured-image.png
How TeamPCP Poisoned Six Python Packages and Breached Over 1000 Organizations in Five Weeks

April 23, 2026

A group of attackers has been quietly poisoning Python packages for five weeks straight. They have exfiltrated data from over 500,000 infected machines, hit …