HTTP Request Smuggling Vulnerability in Elixir Mint HTTP Client
CVE-2026-82672
What is CVE-2026-82672?
The Elixir Mint HTTP client is susceptible to an HTTP Request Smuggling vulnerability that arises from inconsistent interpretation of chunked HTTP responses. In a pooled connection scenario, a malicious HTTP/1 server can exploit this inconsistency to desynchronize the Mint client and a strict intermediary, causing response-queue poisoning. Specifically, the Mint client improperly processes chunk sizes, allowing non-hexadecimal characters and malformed chunk sizes to pass undetected. This discrepancy leads to conflicts in chunk boundaries and may compromise subsequent requests sharing the same connection. Affected versions include Mint from 0.1.0 up to but not including 1.10.1. For more details, refer to the advisory and commits addressing this issue.
Affected Version(s)
mint 0.1.0 < 1.10.1
mint 60089586ec7adc9fddb09f69a2f5919ba9ac7f33
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
