HTTP Request Smuggling Vulnerability in Elixir Mint
CVE-2026-94194

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-94194?

An inconsistency in HTTP request handling within Elixir Mint can lead to a serious security issue where a malicious HTTP/1 server can disrupt communication between an intermediary and the Mint client. This flaw allows the potential poisoning of responses to future requests sharing the same connection. Due to its improper interpretation of Transfer-Encoding headers, the Mint library miscalculates the end of HTTP responses, which can result in data leaks or manipulated responses affecting application integrity. This vulnerability impacts versions from 0.1.0 up to but not including 1.11.0, requiring immediate attention to ensure secure communication.

Affected Version(s)

mint 0.1.0 < 1.11.0

mint 60089586ec7adc9fddb09f69a2f5919ba9ac7f33 < 2ec8b696b5475ecbdaa87c0098957bca339e17c0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx
zx
Eric Meadows-Jönsson
.