Junglewise Threat Intelligence

CVE-2026-82728: Elixir Mint HTTP/1 parser denial of service via unbounded buffer

CVE-2026-82728 · Severity: info · CVSS 7.5 · Published 2026-09-04

Technologies: Elixir-Mint Mint. Vendors: Elixir-Mint.

Executive brief

Elixir Mint is an HTTP client library used to make web requests from Elixir applications. A malicious HTTP server can send crafted responses that cause the client to indefinitely accumulate data in memory without any size limit, eventually exhausting available memory and crashing the application. An attacker can exploit this by hosting a malicious server or redirecting the application to one they control.

Technical details

The vulnerability is an Allocation of Resources Without Limits or Throttling (CWE-770) in the HTTP/1 response parser. Two code paths in lib/mint/http1.ex accumulate unconsumed server data in conn.buffer without enforcing limits: decode_status_line/4 when a status line is incomplete (waiting for CRLF), and decode_body/5 when a chunk-extension line is unterminated. The :max_header_list_size budget is only applied to decode_headers/5 and decode_trailer_headers/4, leaving these two states unprotected. A remote attacker controlling an HTTP server (or reached via redirect) can stream bytes indefinitely, causing memory exhaustion and denial of service. The chunk-extension variant is reachable after a valid status line and complete headers, so intermediaries inspecting only headers will not detect the attack.

Affected products

  • Elixir Mint Mint 0.1.0 before 1.10.0

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: Fix available in version 1.10.0

References

Related threats