Executive brief
Mint is an HTTP client library for Elixir used in applications that make HTTP requests. A malicious HTTP/2 server can cause the Mint client to accumulate approximately 16 MB of data in memory by declaring oversized frames and withholding the final bytes, leading to uncontrolled memory consumption and potential denial of service.
Technical details
The vulnerability exists in Mint.HTTP2.Frame.decode_next/2, which validates frame size only after the complete declared payload arrives. An attacker can send frames declaring lengths up to 16,777,215 bytes (the 24-bit limit) and delay the final byte, causing the client to buffer approximately 1,024 times the default max frame size (16 KB) per connection. This is a resource exhaustion issue requiring network proximity and an active HTTP/2 connection, with no amplification as the server must send all buffered bytes.
Affected products
- elixir-mint Mint 0.1.0 before 1.11.0
Timeline
- 2026-09-28: disclosed