CVE-2026-65623 | mtrudel bandit up to 1.12.0 WebSocket Fragment Reassembly connection.ex resource consumption

SecurityVulns

A vulnerability classified as problematic has been found in mtrudel bandit up to 1.12.0. The impacted element is the function Elixir.Bandit.WebSocket.Connection.oversize_message?/2 of the file lib/bandit/websocket/connection.ex of the component WebSocket Fragment Reassembly. Performing a manipulation results in resource consumption.

This vulnerability was named CVE-2026-65623. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More