CVE-2026-94194
Received Received - Intake

HTTP Request Smuggling in Mint HTTP Client

Vulnerability report for CVE-2026-94194, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: EEF

Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.11.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elixir-mint mint From 0.1.0 (inc) to 1.11.0 (exc)
elixir-mint mint to 1.11.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-94194 is an HTTP request/response smuggling vulnerability in the elixir-mint library affecting versions before 1.11.0. The issue occurs because Mint incorrectly parses HTTP/1 responses by checking the first Transfer-Encoding token instead of the last, violating RFC 9112. This causes Mint to misinterpret response bodies, leading to desynchronization between intermediaries and the Mint client on pooled connections. Attackers can exploit this by sending crafted responses to poison subsequent requests.

Detection Guidance

Detecting this vulnerability requires checking if your system uses elixir-mint versions prior to 1.11.0. Inspect Elixir project dependencies for mint with command: mix deps | grep mint. If mint is listed with version <1.11.0, the system is vulnerable. Network detection involves monitoring HTTP/1 responses with Transfer-Encoding headers like chunked, gzip to identify improper parsing behavior.

Impact Analysis

This vulnerability could allow attackers to manipulate responses intended for other users, leading to data leakage or unauthorized access. It may also cause connection exhaustion or corruption of pipelined requests, disrupting service functionality. Applications using vulnerable Mint versions could receive incorrect data, affecting user sessions or system operations.

Compliance Impact

This vulnerability could lead to data leakage or manipulation of responses, which may violate confidentiality requirements in GDPR and HIPAA. By desynchronizing connections, attackers might access or alter sensitive data in transit, undermining compliance with data protection standards.

Mitigation Strategies

Immediately update elixir-mint to version 1.11.0 or later using mix deps.update mint. If updating is not possible, restrict use of HTTP/1 connections or implement strict Transfer-Encoding header validation in intermediaries. Monitor network traffic for suspicious responses with malformed Transfer-Encoding headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94194. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart