Executive brief
A vulnerability in the hpax library, which handles HTTP/2 header compression for Elixir-based web servers, allows an attacker to crash or slow down a server. By sending a specially crafted, small request, an attacker can force the server to perform massive amounts of unnecessary calculation, leading to a denial-of-service. This can disrupt business operations by making web services unavailable to legitimate users.
Technical details
The hpax library fails to enforce an upper bound on the number of continuation octets or the final value during HPACK variable-length integer decoding. Specifically, the 'Elixir.HPAX.Types':decode_remaining_integer/3 function processes continuation octets using arbitrary-precision BEAM integers. Because each octet triggers a bit-shift and addition into an increasingly large bignum, the decoding cost grows superlinearly (O(N^2)). An unauthenticated remote attacker can exploit this by sending a small HTTP/2 header block containing a long run of continuation octets, resulting in excessive CPU and memory consumption. The issue is fixed in version 1.0.4.
Affected products
- elixir-mint hpax 0.1.1 to 1.0.3
Timeline
- 2026-07-05: advisory: GitHub Security Advisory published
- 2026-07-06: disclosed: CVE published to NVD
- 2026-07-06: patched: Fix committed to repository