bandit
1.11.0
A pure-Elixir HTTP server built for Plug & WebSock apps
Current section
10 Advisories
Jump to
Current section
10 Advisories
Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion
Affected Versions
References
- https://github.com/mtrudel/bandit/security/advisories/GHSA-q6v9-r226-v65f
- https://cna.erlef.org/cves/CVE-2026-42788.html
- https://github.com/mtrudel/bandit/commit/1e8e55966da9129016b73d32f0e1df4630e3b463
- https://nvd.nist.gov/vuln/detail/CVE-2026-42788
- https://osv.dev/vulnerability/EEF-CVE-2026-42788
- https://github.com/mtrudel/bandit
Bandit trusts client-supplied URI scheme on plaintext connections
Affected Versions
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-39807
- https://github.com/mtrudel/bandit/security/advisories/GHSA-375f-4r2h-f99j
- https://github.com/mtrudel/bandit/commit/45feea20dea8af7ffd7245271107b695c040e667
- https://cna.erlef.org/cves/CVE-2026-39807.html
- https://github.com/mtrudel/bandit
- https://osv.dev/vulnerability/EEF-CVE-2026-39807
Bandit is vulnerable to CL.CL request smuggling via unrejected duplicate `Content-Length` header
Affected Versions
References
- https://github.com/mtrudel/bandit/security/advisories/GHSA-c67r-gc9j-2qf7
- https://github.com/mtrudel/bandit/commit/f2ca636eb6df385219957e8934e9fc6efa1630d1
- https://github.com/mtrudel/bandit
- https://cna.erlef.org/cves/CVE-2026-39805.html
- https://osv.dev/vulnerability/EEF-CVE-2026-39805
- https://nvd.nist.gov/vuln/detail/CVE-2026-39805
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-42786.html
- https://osv.dev/vulnerability/EEF-CVE-2026-42786
- https://github.com/mtrudel/bandit/security/advisories/GHSA-pf94-94m9-536p
- https://nvd.nist.gov/vuln/detail/CVE-2026-42786
- https://github.com/mtrudel/bandit/commit/21612c7c7b1ce43eccd36d3af3a2299d23513667
- https://github.com/mtrudel/bandit
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-39804.html
- https://osv.dev/vulnerability/EEF-CVE-2026-39804
- https://github.com/mtrudel/bandit/security/advisories/GHSA-frh3-6pv6-rc8j
- https://nvd.nist.gov/vuln/detail/CVE-2026-39804
- https://github.com/mtrudel/bandit/commit/8156921a51e684a951221da7bc30a70a022f722e
- https://github.com/mtrudel/bandit
CL.CL HTTP request smuggling via duplicate Content-Length in bandit
Affected Versions
WebSocket permessage-deflate inflate has no output-size cap in bandit
Affected Versions
Client-supplied URI scheme trusted without transport verification in bandit
Affected Versions
WebSocket fragmented message reassembly unbounded in bandit
Affected Versions
HTTP/2 frame size limit checked after body is buffered in bandit
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
52 796
yesterday
27 407
last 7 days
163 545
all time
10 587 461