Executive brief
Bandit, a high-performance web server for the Elixir programming language, is vulnerable to a request smuggling flaw. When the server receives a request with multiple 'Content-Length' headers, it incorrectly processes only the first one instead of rejecting the request as required by web standards. This allows an attacker to hide a second, unauthorized request inside a legitimate one, potentially bypassing security filters, firewalls, or access controls.
Technical details
The vulnerability exists in 'Elixir.Bandit.Headers':get_content_length/1 within lib/bandit/headers.ex, which utilizes List.keyfind/3 to retrieve the Content-Length header. Because List.keyfind/3 only returns the first occurrence, Bandit fails to detect and reject requests containing multiple, conflicting Content-Length headers as required by RFC 9112 §6.3. If Bandit is deployed behind a proxy that prioritizes the last Content-Length header, an unauthenticated attacker can craft a request where the trailing bytes are interpreted by Bandit as a separate, pipelined request. This enables the smuggling of requests past WAFs, ACLs, and rate limiters. The issue is resolved in version 1.11.0.
Affected products
- mtrudel bandit < 1.11.0
Timeline
- 2026-05-01: advisory: GHSA-c67r-gc9j-2qf7 published
- 2026-05-01: patched: Version 1.11.0 released