Junglewise Threat Intelligence

CVE-2026-39805: mtrudel bandit HTTP request smuggling via duplicate Content-Length

CVE-2026-39805 · Severity: info · CVSS 6.3 · Published 2026-05-01

Technologies: Mtrudel Bandit. Vendors: Mat Trudel.

Executive brief

Bandit, a high-performance web server for the Elixir programming language, is vulnerable to a request smuggling flaw. When the server receives a request with multiple 'Content-Length' headers, it incorrectly processes only the first one instead of rejecting the request as required by web standards. This allows an attacker to hide a second, unauthorized request inside a legitimate one, potentially bypassing security filters, firewalls, or access controls.

Technical details

The vulnerability exists in 'Elixir.Bandit.Headers':get_content_length/1 within lib/bandit/headers.ex, which utilizes List.keyfind/3 to retrieve the Content-Length header. Because List.keyfind/3 only returns the first occurrence, Bandit fails to detect and reject requests containing multiple, conflicting Content-Length headers as required by RFC 9112 §6.3. If Bandit is deployed behind a proxy that prioritizes the last Content-Length header, an unauthenticated attacker can craft a request where the trailing bytes are interpreted by Bandit as a separate, pipelined request. This enables the smuggling of requests past WAFs, ACLs, and rate limiters. The issue is resolved in version 1.11.0.

Affected products

  • mtrudel bandit < 1.11.0

Timeline

  • 2026-05-01: advisory: GHSA-c67r-gc9j-2qf7 published
  • 2026-05-01: patched: Version 1.11.0 released

References

Related threats