Junglewise Threat Intelligence

CVE-2026-94194: Mint HTTP request/response smuggling in transfer encoding parsing

CVE-2026-94194 · Severity: info · Published 2026-09-28

Technologies: Elixir-Mint Mint. Vendors: Elixir-Mint.

Executive brief

Mint is an Elixir HTTP client library used to make requests to web services. A malicious or compromised HTTP server can send specially crafted responses that cause Mint to misinterpret message boundaries on connection pools, leading it to associate responses with incorrect requests. An attacker could use this to poison responses seen by legitimate application code, potentially causing data leakage, request injection, or application logic bypass.

Technical details

The vulnerability exists in message_body/1 in lib/mint/http1.ex, which applies chunked transfer encoding when chunked appears first in the Transfer-Encoding header, contrary to RFC 9112 section 6.3 which requires it be final. Additionally, Mint incorrectly keeps connections open after HTTP/1.0 responses with Transfer-Encoding and Connection: keep-alive, violating RFC 9112 section 6.1. Both cases allow an attacker-controlled server to desynchronize the client and intermediaries on pooled connections, causing response poisoning for subsequent requests sharing the same connection.

Affected products

  • elixir-mint mint 0.1.0 before 1.11.0

Timeline

  • 2026-09-28: disclosed

References

Related threats