Two high-severity denial-of-service vulnerabilities have been disclosed in mtrudel Bandit that let unauthenticated remote attackers exhaust server memory through WebSocket handling. CVE-2026-42786 affects Bandit versions 0.5.0 before 1.11.0 and stems from unbounded accumulation of fragmented WebSocket continuation frames in Elixir.Bandit.WebSocket.Connection.handle_frame/3; Bandit appends fragments to a per-connection iolist without any cumulative size limit, so an attacker can keep sending fin: false frames until the BEAM node runs out of memory. The issue occurs before WebSock.handle_in/2 is reached, preventing application-level checks from stopping the buildup, and it can expose Phoenix Channels and LiveView deployments that accept socket connections.
A second flaw, CVE-2026-39804, affects Bandit versions 0.5.9 before 1.11.0 and is caused by unbounded decompression in Elixir.Bandit.WebSocket.PerMessageDeflate:inflate/2, where :zlib.inflate/2 is used without an output-size cap before the payload is converted into a single binary. A small compressed WebSocket frame can therefore trigger massive memory allocation and potentially an out-of-memory kill before application code executes. This issue is limited to deployments that enable WebSocket compression at both the Bandit server level (websocket_options.compress) and during upgrade (compress: true in WebSockAdapter.upgrade/4); stock Phoenix and LiveView defaults are reported as unaffected because compression is disabled by default.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-39804 was recorded as a high-severity denial-of-service flaw in Elixir.Bandit.WebSocket.PerMessageDeflate:inflate/2. When Bandit's WebSocket compression is enabled, a small compressed frame can decompress into a massive payload and exhaust memory before application code runs.
CVE-2026-42786 was recorded as a high-severity denial-of-service flaw in Elixir.Bandit.WebSocket.Connection.handle_frame/3. An unauthenticated remote attacker can send unlimited continuation frames with fin: false to force unbounded memory allocation before application-level checks occur.
Two denial-of-service vulnerabilities affecting mtrudel Bandit were disclosed as fixed in Bandit 1.11.0: one involving unbounded WebSocket fragmented-message reassembly and another involving unbounded permessage-deflate decompression. The issues affect Bandit versions before 1.11.0, with impacted ranges starting at 0.5.0 for fragmented reassembly and 0.5.9 for permessage-deflate inflation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.