CVE-2026-74836: CWE-770 Allocation of Resources Without Limits or Throttling in mtrudel bandit
Description
CVE-2026-74836 is a high-severity vulnerability in mtrudel bandit affecting versions from 0.3.4 up to but not including 1.12.5. It involves allocation of resources without limits or throttling in the HTTP/2 connection-level flow control. An unauthenticated remote attacker can cause indefinite blocking of HTTP/2 stream processes by exploiting the unbounded queuing of response bytes exceeding the connection-level send window. This leads to resource exhaustion as each stalled stream pins its process and associated resources indefinitely. The vulnerability allows repeated exploitation across multiple streams and connections, potentially causing denial of service.
CVSS v4.0
Score 8.7high
Affected software
mtrudel
bandit
mtrudel
bandit
cpe:2.3:a:mtrudel:bandit:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the HTTP/2 connection-level send window (default 65,535 bytes) is shared across all streams on a connection. When a stream's response body exceeds this window, Bandit.HTTP2.Connection queues the remaining bytes and a reply closure in pending_sends, causing the stream process to block indefinitely inside a synchronous call to the connection process. Unlike the stream-level send window, which has a 15-second bound, the connection-level path has no timeout or purge mechanism. As a result, a client can keep the connection alive with periodic PING frames, preventing transport-level timeouts and causing resource exhaustion by pinning processes and resources such as pooled upstream connections. This affects bandit versions >=0.3.4 and <1.12.5.
Potential Impact
An unauthenticated remote attacker can cause denial of service by exhausting server resources indefinitely. Each stalled HTTP/2 stream process consumes memory and other resources, including pooled upstream connections in reverse-proxy scenarios. The attacker can create multiple stalled streams and connections, leading to significant resource exhaustion and potential service disruption.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, consider limiting the size of responses or implementing external rate limiting on HTTP/2 connections to mitigate resource exhaustion risks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-08-20T14:30:02.109Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a87701facd9273b49247129
Added to database: 08/20/2026, 21:22:39 UTC
Last enriched: 09/10/2026, 21:32:18 UTC
Last updated: 10/04/2026, 18:53:18 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.