Resource Management Flaw in elixir-mint HTTP Client
CVE-2026-92103
What is CVE-2026-92103?
A resource management vulnerability exists in the elixir-mint HTTP client, where malicious HTTP/2 servers can manipulate the client into buffering excessive amounts of data. Specifically, the Mint.HTTP2.Frame.decode_next/2 function allows for unacceptable memory consumption, as it fails to impose limits on incoming frame sizes until the entire declared payload has been received. This allows a server to declare frames of significant size, leading to potential memory exhaustion on the client side while it awaits additional data. This flaw could be exploited by an attacker to hold the HTTP connection open and force the client to allocate resources beyond intended thresholds, potentially impacting the application's performance and stability.
Affected Version(s)
mint 0.1.0 < 1.11.0
mint 596ca4304504be68939c4929e0831557097962b8 < 20252ca85065f4d1092aed9ee4ed21841a507dfe
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
