CVE-2026-39804Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compression is enabled. 'Elixir.Bandit.WebSocket.PerMessageDeflate':inflate/2 in lib/bandit/websocket/permessage_deflate.ex calls :zlib.inflate/2 with no output-size cap, then materializes the entire decompressed payload as a single binary via IO.iodata_to_binary/1. The websocket_options.max_frame_size option only bounds the on-the-wire (compressed) frame size, not the decompressed output. A high-ratio compressed frame (e.g. uniform data at ~1024:1 ratio) can stay well under any wire-size limit while forcing GiB-scale heap allocations in the connection process before any application code runs. An unauthenticated attacker who can open a WebSocket connection can send a single such frame to exhaust the BEAM node's memory and trigger an OOM kill. This vulnerability requires both Bandit's server-level websocket_options.compress and the per-upgrade compress: true option passed to WebSockAdapter.upgrade/4 to be enabled. Stock Phoenix and LiveView applications are not affected as they default to compress: false. This issue affects bandit: from 0.5.9 before 1.11.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 105-0105-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-021
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-39804 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSoc… https://www.cve.org/CVERecord?id=CVE-2026-39804

    Post summary

    The text provides a brief disclosure of CVE-2026-39804, outlining a memory‑exhaustion denial‑of‑service vulnerability in mtrudel bandit.

    00010180
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39804 Unauthenticated Remote Denial of Service via Memory Exhaustion in Bandit WebSocket Compression https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39804

    Post summary

    The text announces CVE-2026-39804, describing an unauthenticated remote denial‑of‑service via memory exhaustion in Bandit WebSocket compression, but provides no PoC, exploit code, or evidence of active exploitation.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39804 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSoc… https://www.cve.org/CVERecord?id=CVE-2026-39804 ----- Traducción: CVE-2026-39804 Asi… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑39804, detailing a memory‑exhaustion denial‑of‑service flaw in mtrudel bandit, without providing PoC, exploit code, or patch information.

    0000026
    75 followersView on X

Explore more