PT-2026-99853 · Hexpm · Elixir-Mint
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
elixir-mint versions 0.1.0 through 1.10.x
Description
A resource allocation issue allows a malicious HTTP/2 server to force a client to buffer up to approximately 16 MiB per connection in frames that should be rejected, leading to excessive client memory consumption. This occurs because the function
decode next/2 in lib/mint/http2/frame.ex only validates the frame against the max frame size variable after the entire declared payload has been received. Until the payload is complete, the system returns :more, causing Mint.HTTP2 to store all received bytes in the connection buffer. A server can declare a frame length up to 16,777,215 bytes and withhold the final byte to maintain this buffer for as long as the connection remains open. This can lead to memory exhaustion for clients maintaining numerous connections to untrusted origins, such as proxies, crawlers, or webhook senders.Recommendations
Update elixir-mint to version 1.11.0 or later.
As a temporary workaround, connect to untrusted origins using HTTP/1 only by setting
protocols: [:http1] in the Mint.HTTP.connect/4 function to avoid the HTTP/2 frame decoder.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elixir-Mint