
CVE-2026-39805 Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers. 'Elixir.Bandit.Heade… https://www.cve.org/CVERecord?id=CVE-2026-39805
Post summary
A new CVE (CVE-2026-39805) for the Elixir.Bandit library is disclosed, detailing HTTP request smuggling via duplicate Content‑Length headers, with no PoC, exploit code, or evidence of active exploitation provided.


