CVE-2026-74836
- EPSS -
- Veröffentlicht 20.08.2026 21:17:09
- Zuletzt bearbeitet 24.08.2026 16:47:56
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes indefinitely via connection-level flow control. When a stream's respo...
CVE-2026-75484
- EPSS -
- Veröffentlicht 20.08.2026 21:17:09
- Zuletzt bearbeitet 24.08.2026 16:47:56
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR, LF, or NUL characters into application-visible request headers via HTTP/2. Bandit.HTTP2.Stream.read_...
CVE-2026-65623
- EPSS 0.39%
- Veröffentlicht 24.07.2026 16:32:24
- Zuletzt bearbeitet 30.07.2026 17:01:07
Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 calle...
CVE-2026-39806
- EPSS 0.64%
- Veröffentlicht 13.05.2026 13:36:17
- Zuletzt bearbeitet 21.05.2026 15:23:08
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex ...
CVE-2026-39803
- EPSS 0.64%
- Veröffentlicht 13.05.2026 13:36:09
- Zuletzt bearbeitet 21.05.2026 15:23:12
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1/socket.ex ...
CVE-2026-39805
- EPSS 0.52%
- Veröffentlicht 01.05.2026 20:34:29
- Zuletzt bearbeitet 24.07.2026 15:17:17
Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers. 'Elixir.Bandit.Headers':get_content_length/1 in lib/bandit/headers.ex uses List.keyfind/3, which returns...
CVE-2026-39804
- EPSS 0.63%
- Veröffentlicht 01.05.2026 20:34:24
- Zuletzt bearbeitet 05.05.2026 19:37:28
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compression is enabled. 'Elixir.Bandit.WebSocket.PerMessageD...
CVE-2026-39807
- EPSS 0.45%
- Veröffentlicht 01.05.2026 20:34:22
- Zuletzt bearbeitet 05.05.2026 19:37:28
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex returns the clie...
CVE-2026-42786
- EPSS 0.55%
- Veröffentlicht 01.05.2026 20:34:17
- Zuletzt bearbeitet 05.05.2026 19:37:28
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/3 in lib/ba...
CVE-2026-42788
- EPSS 0.51%
- Veröffentlicht 01.05.2026 20:34:11
- Zuletzt bearbeitet 05.05.2026 19:37:28
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames. 'Elixir.Bandit.HTTP2.Frame':deserialize/2 in lib/bandit/http2/frame.ex checks the SETTINGS_MAX...