Resource Allocation Flaw in elixir-mint mint Affects Performance
CVE-2026-91043

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-91043?

A resource allocation vulnerability exists in elixir-mint mint that allows a malicious HTTP/2 server to exploit the client's settings, potentially leading to memory exhaustion and service disruption. The vulnerability arises when the max_header_list_size is enforced on the compressed size of inbound header blocks only, not accounting for the total decoded header size as per RFC 9113. Consequently, clients may allocate excessive memory for a single response, which can overwhelm the system's resources, causing a denial of service. Multiple responses can exacerbate the issue, putting both the connection process and the entire virtual machine at risk.

Affected Version(s)

mint 1.1.0 < 1.11.0

mint 8e0e04680476f90f9f68db4dfeabcbe66dabfc4d

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eric Meadows-Jönsson
Eric Meadows-Jönsson
Andrea Leopardi
.