{"containers":{"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Mint.HTTP1.Parse'","'Elixir.Mint.HTTP1'"],"packageName":"mint","packageURL":"pkg:hex/mint","product":"mint","programFiles":["lib/mint/http1/parse.ex","lib/mint/http1.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP1.Parse':chunk_size/1"},{"name":"'Elixir.Mint.HTTP1.Parse':ignore_until_crlf/1"},{"name":"'Elixir.Mint.HTTP1':decode_body/5"}],"repo":"https://github.com/elixir-mint/mint","vendor":"elixir-mint","versions":[{"lessThan":"1.10.1","status":"affected","version":"0.1.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Mint.HTTP1.Parse'","'Elixir.Mint.HTTP1'"],"packageName":"elixir-mint/mint","packageURL":"pkg:github/elixir-mint/mint","product":"mint","programFiles":["lib/mint/http1/parse.ex","lib/mint/http1.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP1.Parse':chunk_size/1"},{"name":"'Elixir.Mint.HTTP1.Parse':ignore_until_crlf/1"},{"name":"'Elixir.Mint.HTTP1':decode_body/5"}],"repo":"https://github.com/elixir-mint/mint","vendor":"elixir-mint","versions":[{"lessThan":"c82377838dc6e275ef40bafa664fbcdf50270c60","status":"affected","version":"60089586ec7adc9fddb09f69a2f5919ba9ac7f33","versionType":"git"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Exploitation requires a deployment topology in which an RFC-strict HTTP/1 intermediary (proxy, load balancer, or WAF) sits between the Mint client and the attacker-influenced origin, and HTTP/1 connections between the client and the intermediary are reused across requests (keep-alive with connection pooling). Mint clients that talk directly to an origin without an intermediary, or that do not reuse connections, are not exploitable for response-queue poisoning even if the vulnerable parsing behavior is present.</p>"},{"base64":false,"type":"text/markdown","value":"Exploitation requires a deployment topology in which an RFC-strict HTTP/1 intermediary (proxy, load balancer, or WAF) sits between the Mint client and the attacker-influenced origin, and HTTP/1 connections between the client and the intermediary are reused across requests (keep-alive with connection pooling). Mint clients that talk directly to an origin without an intermediary, or that do not reuse connections, are not exploitable for response-queue poisoning even if the vulnerable parsing behavior is present."}],"value":"Exploitation requires a deployment topology in which an RFC-strict HTTP/1 intermediary (proxy, load balancer, or WAF) sits between the Mint client and the attacker-influenced origin, and HTTP/1 connections between the client and the intermediary are reused across requests (keep-alive with connection pooling). Mint clients that talk directly to an origin without an intermediary, or that do not reuse connections, are not exploitable for response-queue poisoning even if the vulnerable parsing behavior is present."}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*","versionEndExcluding":"1.10.1","versionStartIncluding":"0.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"finder","value":"Eurico Nicacio"},{"lang":"en","type":"reporter","value":"Eurico Nicacio"},{"lang":"en","type":"remediation developer","value":"Eric Meadows-Jönsson"},{"lang":"en","type":"remediation reviewer","value":"Andrea Leopardi"}],"dateAssigned":"2026-09-19T15:55:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.</p>\n<p><code>Mint.HTTP1.Parse.chunk_size/1</code> in <code>lib/mint/http1/parse.ex</code> stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. <code>Mint.HTTP1.decode_body/5</code> in <code>lib/mint/http1.ex</code> then discards every byte up to the CRLF with <code>Parse.ignore_until_crlf/1</code>, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a <code>;</code>-introduced chunk extension. Lines such as <code>5ZZZZZ</code> and <code>5 9</code> are accepted as chunk size 5, and <code>0ZZZZ</code> is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends.</p>\n<p>This issue affects mint: from 0.1.0 before 1.10.1.</p>"},{"base64":false,"type":"text/markdown","value":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.\n\n`Mint.HTTP1.Parse.chunk_size/1` in `lib/mint/http1/parse.ex` stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. `Mint.HTTP1.decode_body/5` in `lib/mint/http1.ex` then discards every byte up to the CRLF with `Parse.ignore_until_crlf/1`, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a `;`-introduced chunk extension. Lines such as `5ZZZZZ` and `5 9` are accepted as chunk size 5, and `0ZZZZ` is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends.\n\nThis issue affects mint: from 0.1.0 before 1.10.1."}],"value":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.\n\nMint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension. Lines such as 5ZZZZZ and 5 9 are accepted as chunk size 5, and 0ZZZZ is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends.\n\nThis issue affects mint: from 0.1.0 before 1.10.1."}],"impacts":[{"capecId":"CAPEC-273","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>A malicious or attacker-influenced HTTP/1 origin behind an RFC-strict intermediary can make the intermediary and the Mint client disagree on chunk boundaries and on where the response body ends. On a pooled keep-alive connection that disagreement lets bytes from one response be attributed to the next, poisoning the responses returned to unrelated requests that share the connection.</p>"},{"base64":false,"type":"text/markdown","value":"A malicious or attacker-influenced HTTP/1 origin behind an RFC-strict intermediary can make the intermediary and the Mint client disagree on chunk boundaries and on where the response body ends. On a pooled keep-alive connection that disagreement lets bytes from one response be attributed to the next, poisoning the responses returned to unrelated requests that share the connection."}],"value":"A malicious or attacker-influenced HTTP/1 origin behind an RFC-strict intermediary can make the intermediary and the Mint client disagree on chunk boundaries and on where the response body ends. On a pooled keep-alive connection that disagreement lets bytes from one response be attributed to the next, poisoning the responses returned to unrelated requests that share the connection."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-444","description":"CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-19T17:00:31.648Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"GitHub Advisory","tags":["related","vendor-advisory"],"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-rj5m-69wp-cxq9"},{"name":"EEF CNA record for CVE-2026-82672","tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-82672.html"},{"name":"OSV record EEF-CVE-2026-82672","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-82672"},{"name":"Introducing commit 6008958 in elixir-mint/mint","tags":["related"],"url":"https://github.com/elixir-mint/mint/commit/60089586ec7adc9fddb09f69a2f5919ba9ac7f33"},{"name":"Fix commit c823778 in elixir-mint/mint","tags":["patch"],"url":"https://github.com/elixir-mint/mint/commit/c82377838dc6e275ef40bafa664fbcdf50270c60"}],"source":{"discovery":"EXTERNAL"},"title":"Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections","x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ol>\n<li>Start a loopback TCP server that serves one <code>HTTP/1.1 200 OK</code> response with <code>transfer-encoding: chunked</code> and controls the chunk-size line byte for byte.</li>\n<li>Connect with <code>Mint.HTTP1</code> (mint 1.10.0 from Hex), send a request and stream the response.</li>\n<li>Positive controls: chunk-size lines <code>+5</code>, <code>Z5</code> and <code>00000000000000005</code> are refused with <code>:invalid_chunk_size</code>, confirming the build carries the earlier chunk-size fixes.</li>\n<li>Baseline: <code>5</code> and <code>5;name=value</code> are accepted with body <code>hello</code>.</li>\n<li>Finding: <code>5ZZZZZ</code>, <code>5 anything at all</code>, <code>5&lt;TAB&gt;foo</code>, <code>5 9</code> and <code>5}~!</code> are each accepted as chunk size 5 with body <code>hello</code>.</li>\n<li>Terminator: <code>0ZZZZ</code> and <code>0 9</code> in place of the final <code>0</code> chunk are accepted and end the body.</li>\n<li>Contrast: <code>Content-Length: +5</code>, <code>Content-Length: 5ZZZ</code> and <code>Content-Length: 5 9</code> are refused with <code>:invalid_content_length_header</code> in the same run.</li>\n</ol>\n<p>The reporter ran this on Elixir 1.18 / OTP 27 and Elixir 1.18.4 / OTP 28 with identical results.</p>"},{"base64":false,"type":"text/markdown","value":"1. Start a loopback TCP server that serves one `HTTP/1.1 200 OK` response with `transfer-encoding: chunked` and controls the chunk-size line byte for byte.\n2. Connect with `Mint.HTTP1` (mint 1.10.0 from Hex), send a request and stream the response.\n3. Positive controls: chunk-size lines `+5`, `Z5` and `00000000000000005` are refused with `:invalid_chunk_size`, confirming the build carries the earlier chunk-size fixes.\n4. Baseline: `5` and `5;name=value` are accepted with body `hello`.\n5. Finding: `5ZZZZZ`, `5 anything at all`, `5<TAB>foo`, `5 9` and `5}~!` are each accepted as chunk size 5 with body `hello`.\n6. Terminator: `0ZZZZ` and `0 9` in place of the final `0` chunk are accepted and end the body.\n7. Contrast: `Content-Length: +5`, `Content-Length: 5ZZZ` and `Content-Length: 5 9` are refused with `:invalid_content_length_header` in the same run.\n\nThe reporter ran this on Elixir 1.18 / OTP 27 and Elixir 1.18.4 / OTP 28 with identical results."}],"value":"* Start a loopback TCP server that serves one HTTP/1.1 200 OK response with transfer-encoding: chunked and controls the chunk-size line byte for byte.\n* Connect with Mint.HTTP1 (mint 1.10.0 from Hex), send a request and stream the response.\n* Positive controls: chunk-size lines +5, Z5 and 00000000000000005 are refused with :invalid_chunk_size, confirming the build carries the earlier chunk-size fixes.\n* Baseline: 5 and 5;name=value are accepted with body hello.\n* Finding: 5ZZZZZ, 5 anything at all, 5<TAB>foo, 5 9 and 5}~! are each accepted as chunk size 5 with body hello.\n* Terminator: 0ZZZZ and 0 9 in place of the final 0 chunk are accepted and end the body.\n* Contrast: Content-Length: +5, Content-Length: 5ZZZ and Content-Length: 5 9 are refused with :invalid_content_length_header in the same run.\n\nThe reporter ran this on Elixir 1.18 / OTP 27 and Elixir 1.18.4 / OTP 28 with identical results."}],"x_technicalAnalysis":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>1. Chunk-size parsing.</strong> <code>Mint.HTTP1.Parse.chunk_size/1</code> in <code>lib/mint/http1/parse.ex</code> folds leading hexadecimal digits into an accumulator through <code>parse_hex_prefix/3</code> and, on the first byte that is not a hex digit, returns <code>{:ok, size, rest}</code> with <code>rest</code> unexamined. The sign and digit-count checks added by earlier fixes constrain only the digits.</p>\n<p><strong>2. Tail skipping.</strong> The caller, <code>Mint.HTTP1.decode_body/5</code> in <code>lib/mint/http1.ex</code>, hands <code>rest</code> to <code>Parse.ignore_until_crlf/1</code>, which advances over any byte until it finds CRLF. Nothing between the last hex digit and the CRLF is validated, so the accepted grammar is <code>1*HEXDIG *OCTET CRLF</code>, where RFC 9112 section 7.1 allows only an optional <code>;</code>-introduced <code>chunk-ext</code>. The same tolerance applies to the terminating zero-length chunk, which is the token that ends the message body.</p>\n<p><strong>3. Parser disagreement.</strong> The sibling <code>Content-Length</code> parser, <code>Mint.HTTP1.Parse.content_length_header/1</code>, trims trailing whitespace and requires the whole remaining value to be digits, rejecting anything else. An RFC-strict intermediary that rejects or reframes a chunk-size line with a non-extension tail, on a connection where Mint accepts it, yields a framing disagreement about chunk length and, through the terminating chunk, about where the message ends.</p>"},{"base64":false,"type":"text/markdown","value":"**1. Chunk-size parsing.** `Mint.HTTP1.Parse.chunk_size/1` in `lib/mint/http1/parse.ex` folds leading hexadecimal digits into an accumulator through `parse_hex_prefix/3` and, on the first byte that is not a hex digit, returns `{:ok, size, rest}` with `rest` unexamined. The sign and digit-count checks added by earlier fixes constrain only the digits.\n\n**2. Tail skipping.** The caller, `Mint.HTTP1.decode_body/5` in `lib/mint/http1.ex`, hands `rest` to `Parse.ignore_until_crlf/1`, which advances over any byte until it finds CRLF. Nothing between the last hex digit and the CRLF is validated, so the accepted grammar is `1*HEXDIG *OCTET CRLF`, where RFC 9112 section 7.1 allows only an optional `;`-introduced `chunk-ext`. The same tolerance applies to the terminating zero-length chunk, which is the token that ends the message body.\n\n**3. Parser disagreement.** The sibling `Content-Length` parser, `Mint.HTTP1.Parse.content_length_header/1`, trims trailing whitespace and requires the whole remaining value to be digits, rejecting anything else. An RFC-strict intermediary that rejects or reframes a chunk-size line with a non-extension tail, on a connection where Mint accepts it, yields a framing disagreement about chunk length and, through the terminating chunk, about where the message ends."}],"value":"1. Chunk-size parsing. Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex folds leading hexadecimal digits into an accumulator through parse_hex_prefix/3 and, on the first byte that is not a hex digit, returns {:ok, size, rest} with rest unexamined. The sign and digit-count checks added by earlier fixes constrain only the digits.\n\n2. Tail skipping. The caller, Mint.HTTP1.decode_body/5 in lib/mint/http1.ex, hands rest to Parse.ignore_until_crlf/1, which advances over any byte until it finds CRLF. Nothing between the last hex digit and the CRLF is validated, so the accepted grammar is 1*HEXDIG *OCTET CRLF, where RFC 9112 section 7.1 allows only an optional ;-introduced chunk-ext. The same tolerance applies to the terminating zero-length chunk, which is the token that ends the message body.\n\n3. Parser disagreement. The sibling Content-Length parser, Mint.HTTP1.Parse.content_length_header/1, trims trailing whitespace and requires the whole remaining value to be digits, rejecting anything else. An RFC-strict intermediary that rejects or reframes a chunk-size line with a non-extension tail, on a connection where Mint accepts it, yields a framing disagreement about chunk length and, through the terminating chunk, about where the message ends."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-82672","datePublished":"2026-09-19T17:00:31.648Z","dateReserved":"2026-09-17T05:30:01.748Z","dateUpdated":"2026-09-19T17:00:31.648Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"}