EEF-CVE-2026-65623

Source
https://cna.erlef.org/osv/EEF-CVE-2026-65623.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-65623.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-65623
Aliases
  • CVE-2026-65623
  • GHSA-vg8x-66vg-5pxh
Published
2026-07-24T16:32:24.923Z
Modified
2026-07-24T16:56:42.882643714Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
Details

Summary

Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly.

The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/websocket/connection.ex appends each non-final continuation frame to a left-nested iolist and then re-measures the entire accumulated buffer with IO.iodata_length/1 on every frame. Because the buffer grows by one element per frame and is fully re-traversed each time, reassembly work is quadratic (O(n^2)) in the number of continuation frames.

The max_fragmented_message_size limit (default 8 MB) bounds total bytes but not frame count, and each frame can carry as little as one payload byte, so an attacker can send millions of tiny continuation frames using modest bandwidth to pin a CPU core for minutes to hours. Many concurrent connections can starve the whole server of CPU, denying service to legitimate users. The WebSocket read timeout does not help, because it is an idle timeout evaluated between reads and cannot preempt the synchronous reassembly work spent inside a single callback.

This issue affects bandit: from 1.11.0 before 1.12.1.

Configuration

This vulnerability only affects applications that serve WebSocket endpoints through Bandit (including Phoenix applications that use Bandit as the HTTP adapter). Applications that do not upgrade any connections to WebSocket are not affected.

Database specific
{
    "cwe_ids": [
        "CWE-407"
    ],
    "cpe_ids": [
        "cpe:2.3:a:mtrudel:bandit:*:*:*:*:*:*:*:*"
    ],
    "capec_ids": [
        "CAPEC-229"
    ]
}
References
Credits
    • Peter Ullrich - FINDER
    • Mat Trudel - REMEDIATION_DEVELOPER

Affected packages

Hex / bandit

Package

Name
bandit
Purl
pkg:hex/bandit

Affected ranges

Type
SEMVER
Events
Introduced
1.11.0
Fixed
1.12.1

Affected versions

1.*
1.11.0
1.11.1
1.12.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-65623.json"

Git / github.com/mtrudel/bandit

Affected ranges

Type
GIT
Repo
https://github.com/mtrudel/bandit
Events

Affected versions

1.*
1.11.0
1.11.1
1.12.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-65623.json"