Resource Management Flaw in elixir-mint HTTP Client
CVE-2026-92103

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-92103?

A resource management vulnerability exists in the elixir-mint HTTP client, where malicious HTTP/2 servers can manipulate the client into buffering excessive amounts of data. Specifically, the Mint.HTTP2.Frame.decode_next/2 function allows for unacceptable memory consumption, as it fails to impose limits on incoming frame sizes until the entire declared payload has been received. This allows a server to declare frames of significant size, leading to potential memory exhaustion on the client side while it awaits additional data. This flaw could be exploited by an attacker to hold the HTTP connection open and force the client to allocate resources beyond intended thresholds, potentially impacting the application's performance and stability.

Affected Version(s)

mint 0.1.0 < 1.11.0

mint 596ca4304504be68939c4929e0831557097962b8 < 20252ca85065f4d1092aed9ee4ed21841a507dfe

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx
zx
Andrea Leopardi
Eric Meadows-Jönsson
.