Executive brief
Mint is an HTTP client library for Elixir used to make network requests. A malicious HTTP/2 server can send specially crafted responses that cause the Mint client to allocate excessive memory, consuming gigabytes of RAM and crashing the client application or entire virtual machine. This allows an attacker to mount a denial-of-service attack against applications using vulnerable Mint versions.
Technical details
The vulnerability stems from incorrect header list size enforcement in HTTP/2: Mint validates the compressed wire size against max_header_list_size but RFC 9113 requires validating the decoded header list size. HPACK-indexed fields consume minimal bytes on the wire but expand to up to 4 KB when decoded, and the join_cookie_headers function copies all cookie values into a single binary, allowing a single response under the default 256 KB limit to trigger ~1 GB allocation. An unauthenticated remote attacker can exploit this via network-based HTTP/2 connections without user interaction.
Affected products
- Elixir Mint Mint 1.1.0 to before 1.11.0
Timeline
- 2026-09-28: disclosed