Junglewise Threat Intelligence

CVE-2026-59249: Elixir Mint HTTP response smuggling in HTTP/1 chunk-size parsing

CVE-2026-59249 · Severity: info · CVSS 6.3 · Published 2026-07-16

Technologies: Elixir-Mint Mint. Vendors: Elixir-Mint.

Executive brief

Mint is a low-level HTTP client for the Elixir programming language. A vulnerability in how it handles certain web traffic allows a malicious server to 'smuggle' data into a shared connection. This could lead to a situation where one user receives a response intended for another, potentially exposing sensitive data or causing the application to behave incorrectly.

Technical details

The Mint.HTTP1.decode_body/5 function in lib/mint/http1.ex uses Elixir's Integer.parse(data, 16) to process chunk-size lines. While RFC 7230 forbids sign prefixes in chunk sizes, Integer.parse/2 accepts leading '+' or '-' characters. This discrepancy allows a malicious origin server to desynchronize the Mint client from an RFC-strict intermediary (like a proxy or WAF) on a pooled keep-alive connection. An attacker can use this to poison the response queue, causing the client to attribute injected bytes to subsequent, unrelated requests sharing the same connection. The issue is fixed in version 1.9.3 by implementing a strict HEXDIG-only parser.

Affected products

  • elixir-mint mint >= 0.1.0, < 1.9.3

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory
  • 2026-07-16: patched: Fixed in version 1.9.3

References

Related threats