Developer docs
API playgroundTry for free, no card

Search company profiles

X41 D-Sec

Full company profile

uuid000elpo

Namestring
X41 D-Sec
Legal namestring
X41 D-Sec GmbH
Websiteurl
x41-dsec.de
Company typeenum
Private
Founded yearint
2015
Descriptiontext

X41 D-Sec GmbH is a boutique application security firm headquartered in Aachen, Germany (Soerser Weg 20, 52070 Aachen; HRB19989), founded in 2015 by Markus Vervier, who continues to serve as Managing Director. The company delivers specialized security research and application security services to enterprise and institutional clients across software, financial, government, healthcare, robotics, and VPN verticals. Named customers include Aspera, Avira, GSI (Gesellschaft für Schwerionenforschung), Klinikum Darmstadt, Mullvad VPN, Malwarebytes, SoftBank Robotics, and SecureDrop/Freedom of the Press Foundation. The firm operates with a deliberately flat, small team (1-10 employees) and is privately held with no disclosed institutional funding.

The company's service portfolio spans six core professional offerings — penetration testing, AppSec/source code audits, red teaming, purple teaming, fuzzing, and custom security research — delivered as per-project engagements, either remotely or on-site, with detailed CVSS- and CWE-scored reports and direct developer briefings. Underlying technical assets include a proprietary custom fuzzing framework used in smartcard driver and YARA-classifier research, and internally developed research tools such as BeanStack (a Java stacktrace fingerprinting database released publicly) and AnyZone (a delegated DNS testing tool). GTM is sales-led and enterprise-direct: prospective clients initiate engagement via [email protected] or the website contact form, and a significant share of demand is channeled through a strategic partnership with the Open Source Technology Improvement Fund (OSTIF), which has commissioned audits of CRI-O, Ruby on Rails, nghttp3/ngtcp2, RSTUF, Hickory DNS, libjpeg-turbo, Go TUF, in-toto, c-ares, libcap, simplejson, Envoy, Git, TUF, BIND9, and others.

X41 monetizes exclusively through professional services on a per-engagement basis; no productized SaaS or platform revenue exists and pricing is not publicly disclosed. Demand generation is content-led via the firm's public research blog, lab advisories, downloadable public audit reports, conference presentations at DEF CON/CCC/TROOPERS/Hack.lu/Pass The Salt, and active social presence on GitHub, Twitter/X, LinkedIn, and Mastodon. The firm has accumulated a substantial reputational track record through high-impact vulnerability disclosures, including CVE-2016-2851 in libotr, Signal Private Messenger vulnerabilities (2016), Wire Secure Messenger vulnerabilities (2018), Microsoft Exchange CVE-2020-16875 (2020), YARA integer overflow and buffer overflow findings (2021), Chilkat PRNG CVE-2024-26329 (2024), a CVSS 8.7 LiteLLM sandbox escape (April 2026), and CVE-2026-48710 in the Starlette ASGI framework affecting an estimated 400,000+ dependent projects (May 2026). The company has also authored notable research artifacts such as the Browser Security White Paper commissioned by Google.

Short descriptiontext

X41 D-Sec is a boutique application security firm founded in 2015 in Aachen, Germany, providing penetration testing, source code audits, red teaming, fuzzing, and custom security research to enterprise and institutional clients across software, government, healthcare, and VPN sectors.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersAachen, Germany
HQ citystring
Aachen
HQ countrystring
Germany
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
penetration testing services, application security audits, source code auditing, red teaming services, security research
Industry3 codes
1Penetration Testing, Red Team & Ethical Hacking
CodeEDAOAIAHPrimaryYes
2Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX)
CodeBPAKADACPrimaryNo
3Application Security & Secure Software (DevSecOps)
CodeEDAOAIAKPrimaryNo
NAICS code2 codes
  • Computer Systems Design and Related Services54151
  • Other Computer Related Services541519
SIC code1 code
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Application Security Services
Social media profiles3 records
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model6 records
1Penetration Testing
TypeProfessional Services
Description

Security penetration testing services against networks, services, and systems. Includes black-box, grey-box, and white-box testing approaches. Deliverables include detailed reports with CVSS scores, CWE classifications, and remediation advice.

2Source Code Audits
TypeProfessional Services
Description

Security-focused code reviews conducted on source code with threat modeling and developer briefings. Includes static and dynamic analysis, fuzzing, and CVSS/CWE reporting.

x41-dsec.de
3Red Teaming
TypeProfessional Services
Description

Goal-oriented security assessments including technical hacking, phishing, and physical security testing over extended periods, limited by legal bounds.

x41-dsec.de
4Purple Teaming Exercises
TypeProfessional Services
Description

Collaborative practical exercises where red and blue teams work together. Includes tabletop exercises and real attack simulations in controlled environments.

x41-dsec.de
5Fuzzing Services
TypeProfessional Services
Description

Automated dynamic analysis for flaw-finding, continuous security testing, and custom analysis implementations for infrastructure, software, and hardware components.

x41-dsec.de
6Security Research
TypeProfessional Services
Description

Custom security research and analysis of attack surface and technical mitigations. Includes published whitepapers such as Browser Security White Paper for Google.

x41-dsec.de
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Marketing or Sales, Operations
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

X41 D-Sec is a boutique application security firm that delivers professional security services including penetration testing, source code audits, red teaming, purple teaming, fuzzing, and custom security research. Engagements scope vulnerabilities in software and infrastructure, produce detailed CVSS/CWE-classified reports with remediation advice, and include threat modeling workshops and coordinated vulnerability disclosure. The firm also publishes public audit reports for transparency and develops internal research tools such as the BeanStack Java stacktrace fingerprinting database and AnyZone DNS testing utility.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • Found no vulnerabilities in CRI-O runtime audit - only informational findings about outdated dependencies
+3 more records
Product overview1 text field

X41 D-Sec is a security auditing and research firm offering a portfolio of professional services rather than a unified software product. Core offerings include AppSec/Code Audits, Red Teaming, Penetration Testing, Fuzzing, Purple Teaming, and Security Research services. Additionally, the company develops internal research tools such as BeanStack (Java fingerprinting database) and AnyZone (DNS testing tool). The company also maintains a public advisories lab documenting discovered vulnerabilities.

Product and service8 records
1AppSec / Code Audits
CategoryApplication Security Services
Description

Security source code audits that identify weaknesses in software products through design workshops, threat modeling, and manual code review, using a blend of automated and manual methods with CVSS and CWE reporting.

2Penetration Testing
CategoryApplication Security Services
Description

Manual penetration testing of network-connected systems that mimics real attacks using white-box, grey-box, or black-box approaches, delivered remotely or on-site with detailed CVSS and CWE-scored reports and remediation guidance.

3Red Teaming
CategoryApplication Security Services
Description

Goal-based security testing performed over longer periods with open scope, including technical hacking, phishing, and physical security components to achieve defined objectives.

4Purple Teaming
CategoryApplication Security Services
Description

Collaborative exercises combining Red and Blue team activities, including tabletop exercises and practical attack simulations conducted together with client staff in controlled environments.

5Fuzzing
CategoryApplication Security Services
Description

Automated dynamic analysis for flaw-finding, regression testing, and custom static/dynamic analysis implementations applied to infrastructure, software, and hardware components.

6Security Research
CategoryApplication Security Services
Description

Custom security research and analysis of attack surface and technical mitigations, including commissioned whitepapers such as the Browser Security White Paper produced for Google.

7BeanStack
CategoryResearch Tool
Description

Java stacktrace fingerprinting service and database that extracts version information from Java stack traces for security analysis.

8AnyZone
CategoryResearch Tool
Description

Tool providing delegated DNS zones for testing purposes without requiring manual zone file management.

Scale indicator3 records

Each record includes

Type, Value, Description, Source

Partnership1 partner
Strategic tierCoreTypeStrategic or Co-development Partner
Description

OSTIF is a non-profit organization that sponsors security audits of critical open source projects. X41 has conducted multiple audits for OSTIF including CRI-O, Ruby on Rails, nghttp3/ngtcp2, RSTUF, Hickory DNS, libjpeg-turbo, Go TUF, in-toto, c-ares, libcap, simplejson, and Envoy fuzzing improvements.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Berlin-based boutique application security firm offering penetration tests, code audits, and security research. Direct peer to X41 with comparable boutique size, public audit reports, and AppSec focus.

TypeDirect peer
Description

New York-based boutique security research and consulting firm offering application security audits, cryptography review, and vulnerability research, with a similar high-profile CVE publication profile.

TypeDirect peer
Description

Heidelberg-based independent security research firm offering penetration testing, code reviews, and security consulting; comparable boutique German competitor with overlapping public research output.

TypeDirect peer
Description

Paris-based security research and consulting firm specializing in binary analysis, reverse engineering, and application security audits; a closely comparable boutique peer in Europe.

TypeDirect peer
Description

Berlin-based boutique security firm focused on vulnerability research, code auditing, and reverse engineering, with similar public CVEs and a comparable target market.

TypeDirect peer
Description

US-based boutique offensive security firm offering penetration testing, red teaming, and application security services; comparable service mix and premium positioning.

7Insinuator
TypeDirect peer
Description

German independent security researcher and consultancy performing source code audits, penetration tests, and vulnerability research; very small peer operating in X41's geographic and product segment.

TypeBroad incumbent
Description

Large UK-listed security consultancy offering application security, penetration testing, and red teaming at global scale; not boutique but the dominant incumbent in the same services categories.

TypeBroad incumbent
Description

European cybersecurity consultancy offering penetration testing, code review, and managed security services; larger incumbent serving enterprise clients in DACH and across Europe.

10n.runs AG
TypeDirect peer
Description

German boutique IT security firm offering application security, reverse engineering, and penetration testing with similar service catalog and customer overlap.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat3 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers8 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature3 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles1 record

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

X41 D-Sec

Application Security Servicesx41-dsec.de

X41 D-Sec is a boutique application security firm founded in 2015 in Aachen, Germany, providing penetration testing, source code audits, red teaming, fuzzing, and custom security research to enterprise and institutional clients across software, government, healthcare, and VPN sectors.

What X41 D-Sec does

X41 D-Sec GmbH is a boutique application security firm headquartered in Aachen, Germany (Soerser Weg 20, 52070 Aachen; HRB19989), founded in 2015 by Markus Vervier, who continues to serve as Managing Director. The company delivers specialized security research and application security services to enterprise and institutional clients across software, financial, government, healthcare, robotics, and VPN verticals. Named customers include Aspera, Avira, GSI (Gesellschaft für Schwerionenforschung), Klinikum Darmstadt, Mullvad VPN, Malwarebytes, SoftBank Robotics, and SecureDrop/Freedom of the Press Foundation. The firm operates with a deliberately flat, small team (1-10 employees) and is privately held with no disclosed institutional funding.

The company's service portfolio spans six core professional offerings — penetration testing, AppSec/source code audits, red teaming, purple teaming, fuzzing, and custom security research — delivered as per-project engagements, either remotely or on-site, with detailed CVSS- and CWE-scored reports and direct developer briefings. Underlying technical assets include a proprietary custom fuzzing framework used in smartcard driver and YARA-classifier research, and internally developed research tools such as BeanStack (a Java stacktrace fingerprinting database released publicly) and AnyZone (a delegated DNS testing tool). GTM is sales-led and enterprise-direct: prospective clients initiate engagement via [email protected] or the website contact form, and a significant share of demand is channeled through a strategic partnership with the Open Source Technology Improvement Fund (OSTIF), which has commissioned audits of CRI-O, Ruby on Rails, nghttp3/ngtcp2, RSTUF, Hickory DNS, libjpeg-turbo, Go TUF, in-toto, c-ares, libcap, simplejson, Envoy, Git, TUF, BIND9, and others.

X41 monetizes exclusively through professional services on a per-engagement basis; no productized SaaS or platform revenue exists and pricing is not publicly disclosed. Demand generation is content-led via the firm's public research blog, lab advisories, downloadable public audit reports, conference presentations at DEF CON/CCC/TROOPERS/Hack.lu/Pass The Salt, and active social presence on GitHub, Twitter/X, LinkedIn, and Mastodon. The firm has accumulated a substantial reputational track record through high-impact vulnerability disclosures, including CVE-2016-2851 in libotr, Signal Private Messenger vulnerabilities (2016), Wire Secure Messenger vulnerabilities (2018), Microsoft Exchange CVE-2020-16875 (2020), YARA integer overflow and buffer overflow findings (2021), Chilkat PRNG CVE-2024-26329 (2024), a CVSS 8.7 LiteLLM sandbox escape (April 2026), and CVE-2026-48710 in the Starlette ASGI framework affecting an estimated 400,000+ dependent projects (May 2026). The company has also authored notable research artifacts such as the Browser Security White Paper commissioned by Google.

X41 D-Sec firmographics

Firmographics
Name
X41 D-Sec
Legal name
X41 D-Sec GmbH
Website
https://x41-dsec.de
Company type
Private
Founded year
2015
Operating status
Operating
Headcount range
1–10 employees
Short description
X41 D-Sec is a boutique application security firm founded in 2015 in Aachen, Germany, providing penetration testing, source code audits, red teaming, fuzzing, and custom security research to enterprise and institutional clients across software, government, healthcare, and VPN sectors.
Ownership category
akta.pro rank

X41 D-Sec industry classification

Industry
Product category
Application Security Services
NAICS
Computer Systems Design and Related Services (54151), Other Computer Related Services (541519)
SIC
Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
akta.pro secondary industries
Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Application Security & Secure Software (DevSecOps) (EDAOAIAK)

Keywords

  • Penetration testing services
  • Application security audits
  • Source code auditing
  • Red teaming services
  • Security research

Where X41 D-Sec is headquartered

Location

Headquarters

HQ city
Aachen
HQ country
Germany
HQ region
Europe

Offices1 record

Markets served

X41 D-Sec business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations

Revenue model

  1. Penetration Testing: Security penetration testing services against networks, services, and systems. Includes black-box, grey-box, and white-box testing approaches. Deliverables include detailed reports with CVSS scores, CWE classifications, and remediation advice.
  2. Source Code Audits: Security-focused code reviews conducted on source code with threat modeling and developer briefings. Includes static and dynamic analysis, fuzzing, and CVSS/CWE reporting.
  3. Red Teaming: Goal-oriented security assessments including technical hacking, phishing, and physical security testing over extended periods, limited by legal bounds.
  4. Purple Teaming Exercises: Collaborative practical exercises where red and blue teams work together. Includes tabletop exercises and real attack simulations in controlled environments.
  5. Fuzzing Services: Automated dynamic analysis for flaw-finding, continuous security testing, and custom analysis implementations for infrastructure, software, and hardware components.
  6. Security Research: Custom security research and analysis of attack surface and technical mitigations. Includes published whitepapers such as Browser Security White Paper for Google.

Go-to-market motion2 records

Distribution channels3 records

Marketing channels7 records

X41 D-Sec product offering

Product offering

Core offering

X41 D-Sec is a boutique application security firm that delivers professional security services including penetration testing, source code audits, red teaming, purple teaming, fuzzing, and custom security research. Engagements scope vulnerabilities in software and infrastructure, produce detailed CVSS/CWE-classified reports with remediation advice, and include threat modeling workshops and coordinated vulnerability disclosure. The firm also publishes public audit reports for transparency and develops internal research tools such as the BeanStack Java stacktrace fingerprinting database and AnyZone DNS testing utility.

Product overview

X41 D-Sec is a security auditing and research firm offering a portfolio of professional services rather than a unified software product. Core offerings include AppSec/Code Audits, Red Teaming, Penetration Testing, Fuzzing, Purple Teaming, and Security Research services. Additionally, the company develops internal research tools such as BeanStack (Java fingerprinting database) and AnyZone (DNS testing tool). The company also maintains a public advisories lab documenting discovered vulnerabilities.

Differentiator

Problem solved

Functional benefit

Products and services

  • AppSec / Code Audits Security source code audits that identify weaknesses in software products through design workshops, threat modeling, and manual code review, using a blend of automated and manual methods with CVSS and CWE reporting.
  • Penetration Testing Manual penetration testing of network-connected systems that mimics real attacks using white-box, grey-box, or black-box approaches, delivered remotely or on-site with detailed CVSS and CWE-scored reports and remediation guidance.
  • Red Teaming Goal-based security testing performed over longer periods with open scope, including technical hacking, phishing, and physical security components to achieve defined objectives.
  • Purple Teaming Collaborative exercises combining Red and Blue team activities, including tabletop exercises and practical attack simulations conducted together with client staff in controlled environments.
  • Fuzzing Automated dynamic analysis for flaw-finding, regression testing, and custom static/dynamic analysis implementations applied to infrastructure, software, and hardware components.
  • Security Research Custom security research and analysis of attack surface and technical mitigations, including commissioned whitepapers such as the Browser Security White Paper produced for Google.
  • BeanStack Java stacktrace fingerprinting service and database that extracts version information from Java stack traces for security analysis.
  • AnyZone Tool providing delegated DNS zones for testing purposes without requiring manual zone file management.

Quantifiable outcome

  • Found no vulnerabilities in CRI-O runtime audit - only informational findings about outdated dependencies
  • +3 more outcomes

Companies that use X41 D-Sec

Customer profile

Named customers8 records

Segments4 records

Ideal customer profiles3 records

X41 D-Sec technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature3 records

X41 D-Sec partnerships and signals

Strategic signal

Partnerships

One partnership is on record.

  • Open Source Technology Improvement Fund (OSTIF)coreStrategic or Co-development PartnerOSTIF is a non-profit organization that sponsors security audits of critical open source projects. X41 has conducted multiple audits for OSTIF including CRI-O, Ruby on Rails, nghttp3/ngtcp2, RSTUF, Hickory DNS, libjpeg-turbo, Go TUF, in-toto, c-ares, libcap, simplejson, and Envoy fuzzing improvements.

Scale indicators3 records

Recent moves6 records

Expansion highlights5 records

X41 D-Sec competitors and assessment

Company assessment

Direct peers

  • Cure53: Berlin-based boutique application security firm offering penetration tests, code audits, and security research. Direct peer to X41 with comparable boutique size, public audit reports, and AppSec focus.
  • Trail of Bits: New York-based boutique security research and consulting firm offering application security audits, cryptography review, and vulnerability research, with a similar high-profile CVE publication profile.
  • ERNW Research: Heidelberg-based independent security research firm offering penetration testing, code reviews, and security consulting; comparable boutique German competitor with overlapping public research output.
  • Quarkslab: Paris-based security research and consulting firm specializing in binary analysis, reverse engineering, and application security audits; a closely comparable boutique peer in Europe.
  • Recurity Labs: Berlin-based boutique security firm focused on vulnerability research, code auditing, and reverse engineering, with similar public CVEs and a comparable target market.
  • Bishop Fox: US-based boutique offensive security firm offering penetration testing, red teaming, and application security services; comparable service mix and premium positioning.
  • Insinuator: German independent security researcher and consultancy performing source code audits, penetration tests, and vulnerability research; very small peer operating in X41's geographic and product segment.
  • n.runs AG: German boutique IT security firm offering application security, reverse engineering, and penetration testing with similar service catalog and customer overlap.

Broad incumbents

  • NCC Group: Large UK-listed security consultancy offering application security, penetration testing, and red teaming at global scale; not boutique but the dominant incumbent in the same services categories.
  • SEC Consult: European cybersecurity consultancy offering penetration testing, code review, and managed security services; larger incumbent serving enterprise clients in DACH and across Europe.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat3 records

Key risks6 records

Key highlights7 records

Customer concentration

X41 D-Sec social profiles

Digital presence

X41 D-Sec financial estimates

Financial estimate

Revenue estimate

Valuation estimate

X41 D-Sec leadership team

Management profile

Number of profiles

Profiles1 record

X41 D-Sec funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

X41 D-Sec M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about X41 D-Sec

What does X41 D-Sec do?

X41 D-Sec is a boutique application security firm that delivers professional security services including penetration testing, source code audits, red teaming, purple teaming, fuzzing, and custom security research. Engagements scope vulnerabilities in software and infrastructure, produce detailed CVSS/CWE-classified reports with remediation advice, and include threat modeling workshops and coordinated vulnerability disclosure. The firm also publishes public audit reports for transparency and develops internal research tools such as the BeanStack Java stacktrace fingerprinting database and AnyZone DNS testing utility.

Is X41 D-Sec a public or private company?

X41 D-Sec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.

When was X41 D-Sec founded?

X41 D-Sec was founded in 2015. It employs 1 to 10 people.

Where is X41 D-Sec based?

X41 D-Sec is headquartered in Aachen, Germany, in the Europe region.

How does X41 D-Sec make money?

Six revenue lines are on record. Penetration Testing is the primary driver. The others are source Code Audits, red Teaming, purple Teaming Exercises, fuzzing Services and security Research.

Who are X41 D-Sec's main competitors?

Direct peers on record are Cure53, Trail of Bits, ERNW Research, Quarkslab, Recurity Labs, Bishop Fox, Insinuator and n.runs AG. Broad incumbents are NCC Group and SEC Consult.

Does X41 D-Sec have an API?

No public API is recorded for X41 D-Sec.

What industry is X41 D-Sec in?

X41 D-Sec's product category is Application Security Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 54151 and its SIC code is 7370.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
InfoWorldFastAPI-based AI tools exposed to authentication bypass by flaw in Starlette frameworkCybersecurity researchers at X41 D-Sec discovered a critical authentication-bypass vulnerability in Starlette, the open-source Python framework powering FastAPI, which allows unauthenticated attackers to bypass host-validation protections using a malformed Host header containing special characters. The flaw, tracked as CVE-2026-48710, affects over 400,000 dependent projects and has downstream impact across LLM gateways, MCP servers, model-serving tools, and agent infrastructure, with researchers rating its severity at 7.0 High versus the maintainer's 6.5 Moderate rating. Starlette's maintainer has released a patch in version 1.0.1 after coordinated disclosure through OSTIF, while researchers warn that the vulnerability could chain into SSRF and remote-code-execution in exposed projects.MlqCritical 'BadHost' Flaw in Starlette Exposes Millions of AI Agent Deployments to Auth BypassA critical authentication bypass vulnerability dubbed 'BadHost' (CVE-2026-48710) in the Starlette Python ASGI framework allows unauthenticated attackers to bypass path-based access controls by injecting a single character into the HTTP Host header. The flaw affects all Starlette versions from 0.8.3 through 1.0.0, cascading into FastAPI, vLLM, LiteLLM, MCP servers, Text Generation Inference, and thousands of AI agent deployments that rely on these frameworks. The vulnerability was discovered by German security firm X41 D-Sec during an OSTIF-sponsored audit of vLLM in January 2026; a patch (Starlette 1.0.1) shipped on May 21 with public disclosure the following day, giving operators effectively zero lead time. Security researchers argue the official CVSS score of 6.5 understates the severity given Starlette's dominance in AI infrastructure, with reports suggesting active exploitation is already underway.GIGAZINEA vulnerability in the open-source package 'Starlette,' which is downloaded more than 300 million times a week, has put millions of AI agents at risk.Security firm X41 D-Sec discovered a critical vulnerability (CVE-2026-48710, dubbed "BadHost") in the open-source Starlette framework, which is downloaded over 325 million times weekly and underpins FastAPI, vLLM, LiteLLM, and other widely-used Python AI tools. The flaw allows attackers to bypass path-based authentication by manipulating the HTTP Host header, potentially exposing sensitive data from AI agents including clinical trial databases, email accounts, identity verification records, and cloud infrastructure credentials. Starlette has released version 1.0.1 to address the vulnerability, and X41 D-Sec has published an online scanner to help organizations detect affected systems.