Am I affected?

type your mint version to check

Description

Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service.

parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chunked response's chunk-size field into an arbitrary-precision accumulator with acc * 16 + digit and imposes no limit on the digit count. Because the accumulator grows without bound, the multiplication is not constant time and one pass over N digits costs O(N squared). handle_data/2 prepends conn.buffer and re-parses from the start on every socket message, so a server that dribbles the digits out in small packets makes the client pay that cost repeatedly. A run of roughly 512,000 hex digits costs over ten seconds of CPU in a single pass, measured on stock defaults. The parser reaches this state after a valid status line and a complete, valid header section, so an intermediary inspecting only headers sees an ordinary 200 response.

This issue affects mint: from 1.9.3 before 1.10.0.

Weaknesses & attack patterns

Weakness

CWE-407 · Inefficient Algorithmic Complexity in catalog → MITRE ↗

Attack patterns

CAPEC-130 · Excessive Allocation MITRE ↗

Affected — Hex / mint Hex.pm ↗ Repository ↗

1.9.3 < 1.10.0 affected
every other version: unaffected
cpe cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.Mint.HTTP1.Parse' · 'Elixir.Mint.HTTP1'
source files lib/mint/http1/parse.ex · lib/mint/http1.ex
routines 'Elixir.Mint.HTTP1.Parse':chunk_size/1 · 'Elixir.Mint.HTTP1':decode_body/5

Affected — GitHub / elixir-mint/mint Repository ↗

fc7d165 < bd2a4e7 affected
every other version: unaffected
cpe cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.Mint.HTTP1.Parse' · 'Elixir.Mint.HTTP1'
source files lib/mint/http1/parse.ex · lib/mint/http1.ex
routines 'Elixir.Mint.HTTP1.Parse':chunk_size/1 · 'Elixir.Mint.HTTP1':decode_body/5

References

Credits

Tr3bor Finder Reporter
Andrea Leopardi Remediation developer
Jonatan Männchen / EEF Coordinator

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
« All CVEs