Executive brief
Bandit is an Elixir-based web server used to handle HTTP traffic for applications like Phoenix and Plug. A flaw in how it processes certain types of data transfers (chunked encoding) allows an unauthenticated attacker to crash or freeze the server. By sending a small number of specially crafted requests, an attacker can exhaust the server's resources, making the application unavailable to legitimate users.
Technical details
A vulnerability exists in 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 within lib/bandit/http1/socket.ex. The decoder fails to correctly handle RFC 9112-compliant chunked requests that include trailer fields. When a trailer is present after the last-chunk marker (0\r\n), the socket's match clauses fail to terminate, causing the code to compute a negative byte count and enter an infinite tail-recursion loop. This pins the worker process for the duration of the TCP connection. An attacker can exhaust the entire worker pool with a small number of concurrent connections, rendering the server unresponsive. The issue is fixed in version 1.11.1.
Affected products
- mtrudel bandit from 1.6.1 before 1.11.1
Timeline
- 2026-05-13: disclosed
- 2026-05-13: patched: Fixed in version 1.11.1
- 2026-05-13: advisory