PT-2026-99852 · Mint · Mint
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mint versions 1.1.0 through 1.10.x
Description
A malicious HTTP/2 server can cause a denial of service by exhausting memory on the client host. The issue occurs because
Mint.HTTP2 only enforces the max header list size setting on the compressed size of an inbound header block, rather than the decoded header list as required by RFC 9113. An attacker can use HPACK indexed fields to create a small compressed block that expands into a very large decoded list. Specifically, the join cookie headers/1 function in lib/mint/http2.ex copies every cookie value of a response into a single new binary, which can lead to the allocation of approximately 1 GB for a single response under default settings. This memory exhaustion can crash the process owning the connection or the entire BEAM virtual machine.Recommendations
Update to version 1.11.0 or later.
As a temporary mitigation, lower the
max header list size value within client settings in the Mint.HTTP.connect/4 function to a small value (e.g., 4,096) to bound the response size.
Restrict connections to untrusted servers to HTTP/1 by setting protocols: [:http1] to avoid the HTTP/2 receive path.
Avoid setting max header list size to :infinity.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mint