The number and severity of CVEs published that impact products developed by Mtrudel over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42786HIGH Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion.
The fragment reassembly | May 1, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-39804HIGH Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage | May 1, 2026 | 8.2 | 32 | NO | NO |
CVE-2026-39806HIGH Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion.
'Elixir.Bandi | May 13, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-39803HIGH Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion.
The chunked clause of ' | May 13, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-42788MEDIUM Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames.
'Elixir.Bandit.HTTP2.Fra | May 1, 2026 | 6.9 | 28 | NO | NO |
CVE-2026-39807MEDIUM Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections.
'Elixir.Bandit.P | May 1, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-39805MEDIUM Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers.
'Elixir.Bandit.Headers':get_conten | May 1, 2026 | 6.3 | 27 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mtrudel.
Media articles that mention a CVE ID that affects a product developed by Mtrudel — matched by CVE ID, not by vendor name.