PT-2026-99852 · Mint · Mint

·

CVE-2026-91043

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mint versions 1.1.0 through 1.10.x
Description A malicious HTTP/2 server can cause a denial of service by exhausting memory on the client host. The issue occurs because Mint.HTTP2 only enforces the max header list size setting on the compressed size of an inbound header block, rather than the decoded header list as required by RFC 9113. An attacker can use HPACK indexed fields to create a small compressed block that expands into a very large decoded list. Specifically, the join cookie headers/1 function in lib/mint/http2.ex copies every cookie value of a response into a single new binary, which can lead to the allocation of approximately 1 GB for a single response under default settings. This memory exhaustion can crash the process owning the connection or the entire BEAM virtual machine.
Recommendations Update to version 1.11.0 or later. As a temporary mitigation, lower the max header list size value within client settings in the Mint.HTTP.connect/4 function to a small value (e.g., 4,096) to bound the response size. Restrict connections to untrusted servers to HTTP/1 by setting protocols: [:http1] to avoid the HTTP/2 receive path. Avoid setting max header list size to :infinity.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91043
GHSA-9X8P-QRF4-JQ7G

Affected Products

Mint