HTTP Request Smuggling Vulnerability in mtrudel Bandit Web Server
CVE-2026-39805
What is CVE-2026-39805?
The Bandit web server by mtrudel contains a vulnerability in its handling of HTTP requests, allowing an attacker to exploit situations where duplicate Content-Length headers are present. The library's function mistakenly processes only the first Content-Length header, disregarding subsequent ones. This leads to a scenario where a malicious actor can send specially crafted HTTP requests that bypass security measures like web application firewalls (WAFs) and rate limiting, allowing unauthorized access or manipulation of the server's behavior. This issue is significant when Bandit operates in a server environment that forwards requests without proper validation, potentially allowing the execution of smuggled requests that should have been rejected as errors.
Affected Version(s)
bandit 0.1.0 < 1.11.0
bandit 7bc8d97cd22697c299baa8012b7f419a7606a80c
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
