PT-2026-99853 · Hexpm · Elixir-Mint

·

CVE-2026-92103

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions elixir-mint versions 0.1.0 through 1.10.x
Description A resource allocation issue allows a malicious HTTP/2 server to force a client to buffer up to approximately 16 MiB per connection in frames that should be rejected, leading to excessive client memory consumption. This occurs because the function decode next/2 in lib/mint/http2/frame.ex only validates the frame against the max frame size variable after the entire declared payload has been received. Until the payload is complete, the system returns :more, causing Mint.HTTP2 to store all received bytes in the connection buffer. A server can declare a frame length up to 16,777,215 bytes and withhold the final byte to maintain this buffer for as long as the connection remains open. This can lead to memory exhaustion for clients maintaining numerous connections to untrusted origins, such as proxies, crawlers, or webhook senders.
Recommendations Update elixir-mint to version 1.11.0 or later. As a temporary workaround, connect to untrusted origins using HTTP/1 only by setting protocols: [:http1] in the Mint.HTTP.connect/4 function to avoid the HTTP/2 frame decoder.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92103
GHSA-Q95C-CCQ6-J5J6

Affected Products

Elixir-Mint