CVE-2026-91043
Received Received - Intake

Memory Exhaustion in Mint HTTP/2 Client

Vulnerability report for CVE-2026-91043, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: EEF

Description

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC 9113 section 6.5.2 defines the limit on the decoded header list. An HPACK indexed field costs one byte on the wire and decodes to a dynamic table entry of up to 4 KB, and join_cookie_headers/1 in lib/mint/http2.ex copies every cookie value of a response into one new binary. A header block under the default 256 KB wire limit therefore makes the client allocate about 1 GB for a single response, and several such responses in one delivery exhaust the memory of the process that owns the connection or of the whole VM. This issue affects mint: from 1.1.0 before 1.11.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
elixir-mint mint From 1.1.0 (inc) to 1.11.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Allocation of Resources Without Limits or Throttling issue in the elixir-mint library's HTTP/2 implementation. A malicious HTTP/2 server can exploit improper handling of HPACK-indexed cookie fields to exhaust client memory. Mint enforces the max_header_list_size limit only on compressed header size, not the decoded size as required by RFC 9113. HPACK indexed fields decode to up to 4 KB per byte on the wire, and the join_cookie_headers function copies cookie values into a single binary, causing a single response to allocate up to 1 GB of memory under default settings.

Detection Guidance

Monitor memory usage of Elixir applications using Mint library, particularly those handling HTTP/2 connections. Check for processes consuming excessive memory or crashing due to out-of-memory errors. Use tools like 'htop' or 'ps' to track memory usage of BEAM VM processes.

Impact Analysis

This vulnerability can cause denial of service by exhausting memory on the client host. It affects HTTP/2 clients using Mint, including libraries like Finch, Req, webhook clients, scrapers, and reverse proxies that fetch from untrusted sources. Multiple malicious responses can exhaust the memory of the process owning the connection or the entire BEAM VM, leading to system crashes or service disruption.

Compliance Impact

This vulnerability primarily impacts system availability by enabling denial-of-service attacks through memory exhaustion. It does not directly violate GDPR or HIPAA compliance but could indirectly affect them by disrupting services that handle personal or health data. Unavailability of systems may lead to breaches of data processing timelines or service level agreements.

Mitigation Strategies

Upgrade Mint to version 1.11.0 or later. Alternatively, lower the max_header_list_size setting in your HTTP/2 client configuration or restrict connections to HTTP/1 to avoid the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91043. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart