Impact
The Elixir Mint HTTP client incorrectly parses the tail of a chunk-size line in a chunked HTTP/1 response, accepting any non‑hexadecimal characters after the first set of hex digits as part of the chunk size. This violates RFC 9112, which allows only optional chunk extensions introduced by a semicolon. When a strict intermediary rejects such a malformed line while Mint accepts it, the two sides become desynchronized, allowing an attacker controlling an upstream server to poison the queue of responses on a pooled connection and inject arbitrary data into subsequent requests. The flaw is classified as CWE‑444 and can lead to data leakage or manipulation of response content.
Affected Systems
Elixir’s Mint HTTP client library, versions from the initial 0.1.0 up through any release before 1.10.1, is affected. Applications embedding Mint that use pooled connections to external services are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, indicating moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker that can influence the upstream server to send a malformed chunked response through a strictly enforcing intermediary, causing desynchronization on the client. While precise timing is needed, the potential impact on data integrity and confidentiality makes the risk significant in environments that rely on pooled connections to untrusted HTTP endpoints.
OpenCVE Enrichment