Unauthenticated process pinning via HTTP/2 flow control
Published Aug 20, 2026 · Updated Aug 20, 2026
Denial of service in Bandit before 1.12.5 allows remote attackers to hang HTTP/2 stream processes via connection-level flow control. In Bandit.HTTP2.Connection, finish_data/5 queues unsent bytes and an unblock closure in pending_sends, while Bandit.HTTP2.Stream.send_data/3 waits in a synchronous call with no timeout or queue purge when the connection send window is exhausted. Any endpoint that returns more than the remaining 65,535-byte connection window is reachable; periodic PING frames keep the socket alive, RST_STREAM does not free the blocked stream, and each stalled request can pin Plug state and pooled upstream resources until the attacker stops the connection.
Summary
What happened
Denial of service in Bandit before 1.12.5 allows remote attackers to hang HTTP/2 stream processes via connection-level flow control. In Bandit.HTTP2.Connection, finish_data/5 queues unsent bytes and an unblock closure in pending_sends, while Bandit.HTTP2.Stream.send_data/3 waits in a synchronous call with no timeout or queue purge when the connection send window is exhausted. Any endpoint that returns more than the remaining 65,535-byte connection window is reachable; periodic PING frames keep the socket alive, RST_STREAM does not free the blocked stream, and each stalled request can pin Plug state and pooled upstream resources until the attacker stops the connection.
The record
- CVE
- CVE-2026-74836
- Published
- Aug 20, 2026
- Updated
- Aug 20, 2026
- Vendor
- Mat Trudel
- Product
- Bandit
- Classifications
- CWE-770, CAPEC-130, T1499.003
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 20, 2026CVE publishedPublication date reported by the CVE source.
- Aug 20, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0.3.4 <1.12.5
- Affected versionversion=6feadb31189d18b7dcda6c663112cd3bbaf63a46 <f6914aad14bb1365dd6f306aa592cfb0819bed3e
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- GHSA-xj8g-532w-jv94 ExUnit proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo