HTTP Request Smuggling Vulnerability in Elixir Mint HTTP Client
CVE-2026-82672

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-82672?

The Elixir Mint HTTP client is susceptible to an HTTP Request Smuggling vulnerability that arises from inconsistent interpretation of chunked HTTP responses. In a pooled connection scenario, a malicious HTTP/1 server can exploit this inconsistency to desynchronize the Mint client and a strict intermediary, causing response-queue poisoning. Specifically, the Mint client improperly processes chunk sizes, allowing non-hexadecimal characters and malformed chunk sizes to pass undetected. This discrepancy leads to conflicts in chunk boundaries and may compromise subsequent requests sharing the same connection. Affected versions include Mint from 0.1.0 up to but not including 1.10.1. For more details, refer to the advisory and commits addressing this issue.

Affected Version(s)

mint 0.1.0 < 1.10.1

mint 60089586ec7adc9fddb09f69a2f5919ba9ac7f33

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eurico Nicacio
Eurico Nicacio
Eric Meadows-Jönsson
Andrea Leopardi
.