bandit
1.11.1
A pure-Elixir HTTP server built for Plug & WebSock apps
Current section
7 Advisories
Jump to
Current section
7 Advisories
HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-39806.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/ae3520dfdbfab115c638f8c7f6f6b805db34e1ab
- https://github.com/mtrudel/bandit/security/advisories/GHSA-rf5q-vwxw-gmrf
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-39806
- https://osv.dev/vulnerability/EEF-CVE-2026-39806
HTTP/1 chunked body reader ignores length cap in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-39803.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/ae3520dfdbfab115c638f8c7f6f6b805db34e1ab
- https://github.com/mtrudel/bandit/security/advisories/GHSA-9q9q-324x-93r2
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-39803
- https://osv.dev/vulnerability/EEF-CVE-2026-39803
HTTP/2 frame size limit checked after body is buffered in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-42788.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/1e8e55966da9129016b73d32f0e1df4630e3b463
- https://github.com/mtrudel/bandit/security/advisories/GHSA-q6v9-r226-v65f
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-42788
- https://osv.dev/vulnerability/EEF-CVE-2026-42788
Client-supplied URI scheme trusted without transport verification in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-39807.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/45feea20dea8af7ffd7245271107b695c040e667
- https://github.com/mtrudel/bandit/security/advisories/GHSA-375f-4r2h-f99j
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-39807
- https://osv.dev/vulnerability/EEF-CVE-2026-39807
CL.CL HTTP request smuggling via duplicate Content-Length in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-39805.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/f2ca636eb6df385219957e8934e9fc6efa1630d1
- https://github.com/mtrudel/bandit/security/advisories/GHSA-c67r-gc9j-2qf7
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-39805
- https://osv.dev/vulnerability/EEF-CVE-2026-39805
WebSocket fragmented message reassembly unbounded in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-42786.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/21612c7c7b1ce43eccd36d3af3a2299d23513667
- https://github.com/mtrudel/bandit/security/advisories/GHSA-pf94-94m9-536p
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-42786
- https://osv.dev/vulnerability/EEF-CVE-2026-42786
WebSocket permessage-deflate inflate has no output-size cap in bandit
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-39804.html
- https://github.com/mtrudel/bandit
- https://github.com/mtrudel/bandit/commit/8156921a51e684a951221da7bc30a70a022f722e
- https://github.com/mtrudel/bandit/security/advisories/GHSA-frh3-6pv6-rc8j
- https://hex.pm/packages/bandit
- https://nvd.nist.gov/vuln/detail/CVE-2026-39804
- https://osv.dev/vulnerability/EEF-CVE-2026-39804
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
205 564
yesterday
29 081
last 7 days
183 462
all time
11 117 975