CVE-2026-39807Disclosure

LOWCVSS 6.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex returns the client-supplied URI scheme verbatim, ignoring the transport's secure? flag. HTTP/1.1 absolute-form request targets (e.g. GET https://victim/path HTTP/1.1) and the HTTP/2 :scheme pseudo-header are both attacker-controlled strings that flow through this function. Over a plaintext TCP connection, a client can declare https and Bandit will set conn.scheme = :https even though no TLS was negotiated. Downstream Plug consumers that branch on conn.scheme are silently misled: Plug.SSL's already-secure branch skips its HTTP→HTTPS redirect, cookies emitted with secure: true are sent over plaintext, audit logs record requests as having arrived over HTTPS, and CSRF/SameSite gating may make incorrect decisions. This issue affects bandit: from 1.0.0 before 1.11.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-807

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-02: 2Active Exploitation · 2026-05-02: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 105-0105-02
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-022
Active Exploitation1Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-39807 Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'E… https://www.cve.org/CVERecord?id=CVE-2026-39807

    Post summary

    The text announces CVE-2026-39807, detailing a transport‑state spoofing flaw in mtrudel bandit over plaintext HTTP, but offers no PoC, exploit, patch, or active exploitation evidence.

    00010201
    57.4K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting mtrudel bandit (CVE-2026-39807) https://vuldb.com/vuln/360795/cti

    Post summary

    CTI observations indicate numerous activities targeting CVE‑2026‑39807 (mtrudel bandit), signifying active exploitation in the wild.

    0000056
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39807 Unauthenticated Transport-State Spoofing in Bandit HTTP Server via Untrusted Scheme Input https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39807

    Post summary

    The text announces a newly disclosed vulnerability (CVE‑2026‑39807) affecting Bandit HTTP Server, describing unauthenticated transport‑state spoofing via untrusted scheme input, without any PoC, exploit, or patch information.

    0000053
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39807 Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'E… https://www.cve.org/CVERecord?id=CVE-2026-39807 ----- Traducción: CVE-2026-39807 Dep… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑39807, noting an unauthenticated transport‑state spoofing flaw in mtrudel bandit, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000030
    75 followersView on X

Explore more