mtrudel CVE 脆弱性と CVE 一覧(2)

製品(CPE): — CVE 件数: 2

mtrudel 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to mtrudel, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 12 / 2 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-39806 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer fields between them. When trailers are present, none of the match clauses fit: the catch-all arm compu 6b3ad84c-e1a6-4bf7-a703-f496b71e49db 8.7 0.64% 2026-05-13 2026-05-21
CVE-2026-39803 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1/socket.ex ignores the caller-supplied :length option when reading HTTP/1 chunked request bodies. Instead of capping the accumulated body at the configured limit (e.g. Plug.Parsers' default 8 MB), do_read_chunked_data!/5 buffers every received chunk into an iol 6b3ad84c-e1a6-4bf7-a703-f496b71e49db 8.7 0.64% 2026-05-13 2026-05-21
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence