PT-2026-99854 · Unknown · Elixir-Mint
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
elixir-mint versions 0.1.0 through 1.10.x
Description
An inconsistent interpretation of HTTP requests, known as HTTP Request/Response Smuggling, allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection. This can lead to response poisoning for subsequent requests sharing the same connection. The issue occurs because the
message body/1 function in lib/mint/http1.ex selects chunked framing if chunked is the first coding listed in a response's Transfer-Encoding field, whereas RFC 9112 requires chunked framing only when chunked is the final coding. Additionally, Mint incorrectly keeps connections open after an HTTP/1.0 response that carries Transfer-Encoding and Connection: keep-alive, which violates RFC 9112 requirements to treat such framing as faulty and close the connection.Recommendations
Update elixir-mint to version 1.11.0 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elixir-Mint