bandit
Hex10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting banditpage 1 of 1
- CVE-2026-39803HIGHCVSS 7.5EG 7.5fixed in 1.11.12026-05-13
vulnerable: 1.10.0 ... 1.9.0 (32 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1…
- CVE-2026-39804HIGHCVSS 8.2EG 8.2fixed in 1.11.02026-05-01
vulnerable: 0.5.10 ... 1.9.0 (83 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compression is enabled. 'Elixir.Bandit.WebSocket.…
- CVE-2026-39805MEDIUMCVSS 6.3EG 6.3fixed in 1.11.02026-05-01
vulnerable: 0.1.0 ... 1.9.0 (116 versions)
Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers. 'Elixir.Bandit.Headers':get_content_length/1 in lib/bandit/headers.ex uses List.keyfind/3, wh…
- CVE-2026-39806HIGHCVSS 7.5EG 7.5fixed in 1.11.12026-05-13
vulnerable: 1.10.0 ... 1.9.0 (21 versions)
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1…
- CVE-2026-39807MEDIUMCVSS 6.3EG 6.3fixed in 1.11.02026-05-01
vulnerable: 1.0.0 ... 1.9.0 (41 versions)
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex retur…
- CVE-2026-42786HIGHCVSS 8.7EG 8.7fixed in 1.11.02026-05-01
vulnerable: 0.5.0 ... 1.9.0 (91 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/…
- CVE-2026-42788MEDIUMCVSS 6.9EG 6.9fixed in 1.11.02026-05-01
vulnerable: 0.3.5 ... 1.9.0 (107 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames. 'Elixir.Bandit.HTTP2.Frame':deserialize/2 in lib/bandit/http2/frame.ex checks the S…
- CVE-2026-65623HIGHCVSS 8.7EG 8.7fixed in 1.12.12026-07-24
vulnerable: 1.11.0, 1.11.1, 1.12.0
Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_messa…
- CVE-2026-74836HIGHCVSS 8.7EG 8.7fixed in 1.12.52026-08-20
vulnerable: 0.3.4 ... 1.9.0 (115 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes indefinitely via connection-level flow control. When a str…
- CVE-2026-75484MEDIUMCVSS 6.9EG 6.9fixed in 1.12.52026-08-20
vulnerable: 1.10.0 ... 1.9.0 (38 versions)
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR, LF, or NUL characters into application-visible request headers via HTTP/2. Bandit.HTTP2.S…
Check whether bandit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for bandit CVEs against the assets you own.
Book a Demo →