Junglewise Threat Intelligence

CVE-2026-39806: mtrudel bandit infinite loop in HTTP/1 chunked decoder

CVE-2026-39806 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: Mtrudel Bandit. Vendors: Mat Trudel.

Executive brief

Bandit is an Elixir-based web server used to handle HTTP traffic for applications like Phoenix and Plug. A flaw in how it processes certain types of data transfers (chunked encoding) allows an unauthenticated attacker to crash or freeze the server. By sending a small number of specially crafted requests, an attacker can exhaust the server's resources, making the application unavailable to legitimate users.

Technical details

A vulnerability exists in 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 within lib/bandit/http1/socket.ex. The decoder fails to correctly handle RFC 9112-compliant chunked requests that include trailer fields. When a trailer is present after the last-chunk marker (0\r\n), the socket's match clauses fail to terminate, causing the code to compute a negative byte count and enter an infinite tail-recursion loop. This pins the worker process for the duration of the TCP connection. An attacker can exhaust the entire worker pool with a small number of concurrent connections, rendering the server unresponsive. The issue is fixed in version 1.11.1.

Affected products

  • mtrudel bandit from 1.6.1 before 1.11.1

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: patched: Fixed in version 1.11.1
  • 2026-05-13: advisory

References

Related threats