CVE-2026-75484 | mtrudel bandit 1.11.0/1.11.1/1.12.1 HTTP/2 Header Processing Bandit.HTTP/2.Stream.read_headers crlf injection
A vulnerability was found in mtrudel bandit 1.11.0/1.11.1/1.12.1 and classified as critical. This vulnerability affects the function Bandit.HTTP2.Stream.read_headers of the component HTTP2 Header Processing. Executing a manipulation can lead to crlf injection.
This vulnerability is registered as CVE-2026-75484. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.