Junglewise Threat Intelligence

CVE-2026-56810: Elixir Mint denial of service in Mint.HTTP1 chunked decoder

CVE-2026-56810 · Severity: info · CVSS 8.7 · Published 2026-07-06

Technologies: Elixir-Mint Mint. Vendors: Elixir-Mint.

Executive brief

Elixir Mint, a popular HTTP client library, contains a vulnerability that allows a malicious server to crash the application using it. By sending a specially crafted response that claims to be very large but never finishes, the server can force the client to consume all available system memory. This can lead to a denial-of-service (DoS) condition, affecting the availability of any service that uses Mint to fetch external data, follow redirects, or process webhooks.

Technical details

A resource exhaustion vulnerability exists in the Mint.HTTP1 module of the Elixir Mint library. The root cause is located in the 'decode_body/5' and 'add_body_to_buffer/2' routines, where the decoder parses chunk sizes from a server without an upper bound and buffers all partial fragments in an unbounded iolist until the full declared chunk length is received. An unauthenticated remote attacker can exploit this by serving a response with a massive chunk size (e.g., 2 GiB) and never completing the chunk, bypassing streaming protections and driving the client's memory usage until an out-of-memory (OOM) condition occurs. This affects versions 0.5.0 through 1.9.0 and is fixed in version 1.9.1.

Affected products

  • elixir-mint mint 0.5.0 to 1.9.0

Timeline

  • 2026-07-06: advisory
  • 2026-07-06: disclosed
  • 2026-07-06: patched

References

Related threats