Current section

8 Advisories

Jump to
EEF-CVE-2026-65623 CVE-2026-65623 GHSA-vg8x-66vg-5pxh

Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit

July 24, 2026
CVSS
?
8.7 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 1.11.0 and < 1.12.1

HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit

May 13, 2026

HTTP/2 frame size limit checked after body is buffered in bandit

May 01, 2026

Client-supplied URI scheme trusted without transport verification in bandit

May 01, 2026

CL.CL HTTP request smuggling via duplicate Content-Length in bandit

May 01, 2026

WebSocket permessage-deflate inflate has no output-size cap in bandit

May 01, 2026

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 20K 40K 60K 80K

this version

94 425

yesterday

38 063

last 7 days

249 880

all time

12 914 080

Last Updated

Jul 27, 2026

License

MIT

Build Tools

mix

Publisher

mtrudel mtrudel