Executive brief
Mint, a popular HTTP client for the Elixir programming language, is vulnerable to a denial-of-service attack. A malicious or compromised server can send a flood of "push promise" messages to the client without ever sending the actual data, causing the client to consume all available memory and crash. This affects any application using Mint to connect to untrusted external servers, such as web scrapers or webhook delivery systems.
Technical details
The vulnerability is an unbounded resource allocation (CWE-770) in Mint's HTTP/2 implementation. Specifically, the `handle_push_promise/3` function in `lib/mint/http2.ex` inserts a `:reserved_remote` entry into the connection's stream map for every inbound `PUSH_PROMISE` frame without checking the `max_concurrent_streams` setting. Because the concurrency limit is only enforced when the subsequent `HEADERS` frame arrives, an attacker can flood the client with promises and withhold the headers, causing linear memory growth until the BEAM process crashes. The attack requires no authentication and is possible because HTTP/2 server push is enabled by default in Mint. The issue is fixed in version 1.9.0.
Affected products
- elixir-mint mint >= 0.2.0, < 1.9.0
Timeline
- 2026-06-02: disclosed: NVD and original report date
- 2026-07-09: advisory: GitHub Advisory published
- 2026-07-09: patched: Version 1.9.0 released