CVE-2026-42786Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/3 in lib/bandit/websocket/connection.ex appends every incoming Continuation{fin: false} frame's payload to a per-connection iolist with no cumulative size cap. The existing max_frame_size option only bounds individual frames; a peer that streams an unbounded number of continuation frames without ever setting fin=1 grows BEAM heap linearly until the OS or a supervisor kills the process. Because the accumulation happens before WebSock.handle_in/2 is called, the application has no opportunity to interpose a size check. Phoenix Channels and LiveView both run over WebSock on Bandit, so a stock Phoenix application exposes this surface as soon as it accepts socket connections. This issue affects bandit: from 0.5.0 before 1.11.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-01); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Mentions · 2026-05-03: 2Mentions · 2026-05-14: 1Active Exploitation · 2026-05-03: 2Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-14: 105-0105-0205-0305-14
Signal classification3 categories
Disclosure
350.0%
Active Exploitation
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-021
General1
2026-05-032
Active Exploitation2
2026-05-141
Disclosure1
Full discourse6 posts
  • ADK Cyber@ADKCyber
    Disclosure

    A new high-severity vulnerability (CVE-2026-42786) in Bandit impacts Phoenix apps using WebSocket connections, allowing remote DoS via memory exhaustion. Check for updates and patch to protect your systems. ADK Cyber can help secure your environment. #Cybersecurity

    Post summary

    The post announces a new high‑severity CVE‑2026‑42786 that causes remote denial of service through memory exhaustion in Phoenix apps using WebSocket connections, and urges users to apply available patches.

    0001051
    80 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting mtrudel bandit (CVE-2026-42786) https://vuldb.com/vuln/360789/cti

    Post summary

    The message signals that threat actors are increasingly targeting CVE‑2026‑42786, implying potential active exploitation, though no PoC, exploit code, or detailed technical info is provided.

    0001075
    2.1K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Attackers are actively exploiting CVE-2026-42786 in mtrudel bandit — they can launch remote denial of service attacks. This critical vulnerability demands immediate attention. Patch now. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #SAP https://t.co/IJMTN54y7m

    Post summary

    The post confirms attackers are actively exploiting CVE‑2026‑42786 for remote denial of service, stresses the critical nature of the flaw, and calls for immediate patching.

    0001048
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42786 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragm… https://www.cve.org/CVERecord?id=CVE-2026-42786

    Post summary

    The post announces CVE-2026-42786, describing a resource‑exhaustion vulnerability in mtrudel bandit that permits unauthenticated remote denial of service via memory exhaustion; no PoC, exploit, or patch information is provided.

    00010189
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42786 Unauthenticated Remote Denial of Service via Memory Exhau... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42786 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE‑2026‑42786, describing it as an unauthenticated remote DoS via memory exhaustion, but does not provide PoC, exploit, or patch information. It appears to be a basic vulnerability disclosure without claims of active exploitation.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42786 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragm… https://www.cve.org/CVERecord?id=CVE-2026-42786 ----- Traducción: CVE-2026-42786 Asi… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-42786, describing it as an unauthenticated remote DoS via memory exhaustion in mtrudel bandit, but offers no PoC, exploit, or patch details.

    0000029
    75 followersView on X

Explore more