Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.

Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension. Lines such as 5ZZZZZ and 5 9 are accepted as chunk size 5, and 0ZZZZ is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends.

This issue affects mint: from 0.1.0 before 1.10.1.
Published: 2026-09-19
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Response smuggling and queue poisoning via the HTTP/1 client
Action: Upgrade library
AI Analysis

Impact

The Elixir Mint HTTP client incorrectly parses the tail of a chunk-size line in a chunked HTTP/1 response, accepting any non‑hexadecimal characters after the first set of hex digits as part of the chunk size. This violates RFC 9112, which allows only optional chunk extensions introduced by a semicolon. When a strict intermediary rejects such a malformed line while Mint accepts it, the two sides become desynchronized, allowing an attacker controlling an upstream server to poison the queue of responses on a pooled connection and inject arbitrary data into subsequent requests. The flaw is classified as CWE‑444 and can lead to data leakage or manipulation of response content.

Affected Systems

Elixir’s Mint HTTP client library, versions from the initial 0.1.0 up through any release before 1.10.1, is affected. Applications embedding Mint that use pooled connections to external services are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.3, indicating moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker that can influence the upstream server to send a malformed chunked response through a strictly enforcing intermediary, causing desynchronization on the client. While precise timing is needed, the potential impact on data integrity and confidentiality makes the risk significant in environments that rely on pooled connections to untrusted HTTP endpoints.

Generated by OpenCVE AI on September 19, 2026 at 22:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Mint library to version 1.10.1 or newer to apply the fixed chunk-size parsing logic.
  • If an upgrade is not currently possible, disable or limit persistent pooled connections to untrusted servers and avoid receiving chunked responses from them.
  • Deploy or configure an intermediate proxy or firewall that strictly validates HTTP/1.1 chunked responses so that malformed chunk-size lines are rejected before reaching the Mint client.

Generated by OpenCVE AI on September 19, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection. Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension. Lines such as 5ZZZZZ and 5 9 are accepted as chunk size 5, and 0ZZZZ is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends. This issue affects mint: from 0.1.0 before 1.10.1.
Title Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections
First Time appeared Elixir-mint
Elixir-mint mint
Weaknesses CWE-444
CPEs cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
Vendors & Products Elixir-mint
Elixir-mint mint
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Elixir-mint Mint
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-21T18:30:02.604Z

Reserved: 2026-09-17T05:30:01.748Z

Link: CVE-2026-82672

cve-icon Vulnrichment

Updated: 2026-09-21T18:29:56.642Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T17:16:35.710

Modified: 2026-09-22T19:09:32.273

Link: CVE-2026-82672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')