HTTP Request Smuggling Vulnerability in Elixir Mint
CVE-2026-94194
What is CVE-2026-94194?
An inconsistency in HTTP request handling within Elixir Mint can lead to a serious security issue where a malicious HTTP/1 server can disrupt communication between an intermediary and the Mint client. This flaw allows the potential poisoning of responses to future requests sharing the same connection. Due to its improper interpretation of Transfer-Encoding headers, the Mint library miscalculates the end of HTTP responses, which can result in data leaks or manipulated responses affecting application integrity. This vulnerability impacts versions from 0.1.0 up to but not including 1.11.0, requiring immediate attention to ensure secure communication.
Affected Version(s)
mint 0.1.0 < 1.11.0
mint 60089586ec7adc9fddb09f69a2f5919ba9ac7f33 < 2ec8b696b5475ecbdaa87c0098957bca339e17c0
