A pure-Elixir HTTP server built for Plug & WebSock apps
bandit is deprecated — find an alternative
Update to >= d38cf046c9a3cae4d0f88001c2ceb4143f86366b to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2026-39803 | HTTP/1 chunked body reader ignores length cap in bandit | ae3520dfdbfab115c638f8c7f6f6b805db34e1ab |
| high | CVE-2026-39804 | WebSocket permessage-deflate inflate has no output-size cap in bandit | 8156921a51e684a951221da7bc30a70a022f722e |
| medium | CVE-2026-39805 | CL.CL HTTP request smuggling via duplicate Content-Length in bandit | f2ca636eb6df385219957e8934e9fc6efa1630d1 |
| high | CVE-2026-39806 | HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit | ae3520dfdbfab115c638f8c7f6f6b805db34e1ab |
| medium | CVE-2026-39807 | Client-supplied URI scheme trusted without transport verification in bandit | 45feea20dea8af7ffd7245271107b695c040e667 |
| high | CVE-2026-42786 | WebSocket fragmented message reassembly unbounded in bandit | 21612c7c7b1ce43eccd36d3af3a2299d23513667 |
| medium | CVE-2026-42788 | HTTP/2 frame size limit checked after body is buffered in bandit | 1e8e55966da9129016b73d32f0e1df4630e3b463 |
| high | CVE-2026-65623 | Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit | 418ef7e906192a230ddba112f7a669c87b6b0e3a |
| high | CVE-2026-74836 | HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit | f6914aad14bb1365dd6f306aa592cfb0819bed3e |
| medium | CVE-2026-75484 | HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit | d38cf046c9a3cae4d0f88001c2ceb4143f86366b |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/hex/banditFirst published · 2020-11-05T17:11:46.440731Z
Last updated · 2026-08-20T19:56:55.255909Z