Resource Allocation Flaw in elixir-mint mint Affects Performance
CVE-2026-91043
What is CVE-2026-91043?
A resource allocation vulnerability exists in elixir-mint mint that allows a malicious HTTP/2 server to exploit the client's settings, potentially leading to memory exhaustion and service disruption. The vulnerability arises when the max_header_list_size is enforced on the compressed size of inbound header blocks only, not accounting for the total decoded header size as per RFC 9113. Consequently, clients may allocate excessive memory for a single response, which can overwhelm the system's resources, causing a denial of service. Multiple responses can exacerbate the issue, putting both the connection process and the entire virtual machine at risk.
Affected Version(s)
mint 1.1.0 < 1.11.0
mint 8e0e04680476f90f9f68db4dfeabcbe66dabfc4d
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
