mtrudel CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

mtrudel vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to mtrudel, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-39806 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer fields between them. When trailers are present, none of the match clauses fit: the catch-all arm compu 6b3ad84c-e1a6-4bf7-a703-f496b71e49db 8.7 0.64% 2026-05-13 2026-05-21
CVE-2026-39803 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1/socket.ex ignores the caller-supplied :length option when reading HTTP/1 chunked request bodies. Instead of capping the accumulated body at the configured limit (e.g. Plug.Parsers' default 8 MB), do_read_chunked_data!/5 buffers every received chunk into an iol 6b3ad84c-e1a6-4bf7-a703-f496b71e49db 8.7 0.64% 2026-05-13 2026-05-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence