“BadHost” was found in Starlette, a package with 325 million weekly downloads.
First seen on arstechnica.com
Jump to article: arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-package/
![]()

