bandit
Hex10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting banditpage 1 of 1
- CVE-2026-39803HIGHCVSS 7.5EG 7.5✓ Fixed in 1.11.12026-05-13
vulnerable: 1.10.0 ... 1.9.0 (32 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1…
- CVE-2026-39804HIGHCVSS 8.2EG 8.2✓ Fixed in 1.11.02026-05-01
vulnerable: 0.5.10 ... 1.9.0 (83 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compression is enabled. 'Elixir.Bandit.WebSocket.…
- CVE-2026-39805MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.11.02026-05-01
vulnerable: 0.1.0 ... 1.9.0 (116 versions)
Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers. 'Elixir.Bandit.Headers':get_content_length/1 in lib/bandit/headers.ex uses List.keyfind/3, wh…
- CVE-2026-39806HIGHCVSS 7.5EG 7.5✓ Fixed in 1.11.12026-05-13
vulnerable: 1.10.0 ... 1.9.0 (21 versions)
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1…
- CVE-2026-39807MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.11.02026-05-01
vulnerable: 1.0.0 ... 1.9.0 (41 versions)
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex retur…
- CVE-2026-42786HIGHCVSS 8.7EG 8.7✓ Fixed in 1.11.02026-05-01
vulnerable: 0.5.0 ... 1.9.0 (91 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/…
- CVE-2026-42788MEDIUMCVSS 6.9EG 6.9✓ Fixed in 1.11.02026-05-01
vulnerable: 0.3.5 ... 1.9.0 (107 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames. 'Elixir.Bandit.HTTP2.Frame':deserialize/2 in lib/bandit/http2/frame.ex checks the S…
- CVE-2026-65623HIGHCVSS 8.7EG 8.7✓ Fixed in 1.12.12026-07-24
vulnerable: 1.11.0, 1.11.1, 1.12.0
Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_messa…
- CVE-2026-74836HIGHCVSS 8.7EG 8.7✓ Fixed in 1.12.52026-08-20
vulnerable: 0.3.4 ... 1.9.0 (115 versions)
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes indefinitely via connection-level flow control. When a str…
- CVE-2026-75484MEDIUMCVSS 6.9EG 6.9✓ Fixed in 1.12.52026-08-20
vulnerable: 1.10.0 ... 1.9.0 (38 versions)
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR, LF, or NUL characters into application-visible request headers via HTTP/2. Bandit.HTTP2.S…
Check whether bandit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for bandit CVEs against the assets you own.
Start Free Scan →