depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/hex/bandit

bandit

hexv1.12.0deprecated

A pure-Elixir HTTP server built for Plug & WebSock apps

License MITpermissive119 versions2 maintainers0 deps187,173 weekly dl
mtrudel/bandit
27
/ 100
Health
find alternative

bandit is deprecated — find an alternative

Update to >= 1e8e55966da9129016b73d32f0e1df4630e3b463 to fix known vulnerabilities

  • Moderate health score (27/100) — verify manually
  • 4 high severity vulnerabilities
  • Package is deprecated
Health breakdown0 – 100
25/25
maintenance
14/20
popularity
0/25
security
15/15
maturity
3/15
community
Vulnerabilities
7
4 high3 medium
Advisories (7)
SeverityIDSummaryFixed in
highCVE-2026-39803HTTP/1 chunked body reader ignores length cap in banditae3520dfdbfab115c638f8c7f6f6b805db34e1ab
highCVE-2026-39804WebSocket permessage-deflate inflate has no output-size cap in bandit8156921a51e684a951221da7bc30a70a022f722e
mediumCVE-2026-39805CL.CL HTTP request smuggling via duplicate Content-Length in banditf2ca636eb6df385219957e8934e9fc6efa1630d1
highCVE-2026-39806HTTP/1 chunked decoder infinite loop on requests with trailer fields in banditae3520dfdbfab115c638f8c7f6f6b805db34e1ab
mediumCVE-2026-39807Client-supplied URI scheme trusted without transport verification in bandit45feea20dea8af7ffd7245271107b695c040e667
highCVE-2026-42786WebSocket fragmented message reassembly unbounded in bandit21612c7c7b1ce43eccd36d3af3a2299d23513667
mediumCVE-2026-42788HTTP/2 frame size limit checked after body is buffered in bandit1e8e55966da9129016b73d32f0e1df4630e3b463
Maintainer trust
Active maintainers (3m)
5
Contributors (12m)
12
Primary author dominance
50%
GitHub stars
1,889

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/hex/bandit

First published · 2020-11-05T17:11:46.440731Z

Last updated · 2026-06-06T23:21:05.672746Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents