CVE-2026-92103
Received Received - Intake

Memory Exhaustion in Mint HTTP/2 Client

Vulnerability report for CVE-2026-92103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: EEF

Description

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory. Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the client's max_frame_size (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns :more, and Mint.HTTP2 keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit. This issue affects mint: from 0.1.0 before 1.11.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elixir-mint mint From 0.1.0 (inc) to 1.11.0 (exc)
elixir-mint mint From 0.1.0 (inc) to 1.10.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the elixir-mint library allows a malicious HTTP/2 server to consume excessive client memory by sending oversized frames. The client buffers up to 16 MiB per connection before enforcing the maximum frame size limit of 16,384 bytes, leading to potential memory exhaustion.

Detection Guidance

Detecting this vulnerability requires checking if your system uses vulnerable versions of elixir-mint (0.1.0 to before 1.11.0). Inspect Elixir project dependencies with mix deps or check version in mix.lock. Monitor memory usage for unexpected spikes during HTTP/2 connections.

Impact Analysis

This vulnerability can cause memory exhaustion on the client side, potentially leading to crashes or degraded performance. It is particularly dangerous for services managing multiple HTTP/2 connections, such as webhook senders or proxies, as it can exhaust system resources.

Compliance Impact

This vulnerability primarily enables remote denial-of-service (DoS) attacks by exhausting client memory, which could indirectly impact compliance with standards like GDPR or HIPAA by disrupting service availability or integrity. However, the CVE data does not explicitly link this issue to compliance requirements or data protection impacts.

Mitigation Strategies

Upgrade elixir-mint to version 1.11.0 or later. Alternatively, restrict HTTP/2 connections to HTTP/1 only to avoid the vulnerable frame decoder. Review and update all dependencies to ensure no vulnerable versions are in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart