{"containers":{"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Mint.HTTP2.Frame'","'Elixir.Mint.HTTP2'"],"packageName":"mint","packageURL":"pkg:hex/mint","product":"mint","programFiles":["lib/mint/http2/frame.ex","lib/mint/http2.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP2.Frame':decode_next/2"},{"name":"'Elixir.Mint.HTTP2':stream/2"},{"name":"'Elixir.Mint.HTTP2':recv/3"},{"name":"'Elixir.Mint.HTTP2':handle_new_data/3"}],"repo":"https://github.com/elixir-mint/mint","vendor":"elixir-mint","versions":[{"lessThan":"1.11.0","status":"affected","version":"0.1.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Mint.HTTP2.Frame'","'Elixir.Mint.HTTP2'"],"packageName":"elixir-mint/mint","packageURL":"pkg:github/elixir-mint/mint","product":"mint","programFiles":["lib/mint/http2/frame.ex","lib/mint/http2.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP2.Frame':decode_next/2"},{"name":"'Elixir.Mint.HTTP2':stream/2"},{"name":"'Elixir.Mint.HTTP2':recv/3"},{"name":"'Elixir.Mint.HTTP2':handle_new_data/3"}],"repo":"https://github.com/elixir-mint/mint","vendor":"elixir-mint","versions":[{"lessThan":"20252ca85065f4d1092aed9ee4ed21841a507dfe","status":"affected","version":"596ca4304504be68939c4929e0831557097962b8","versionType":"git"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*","versionEndExcluding":"1.11.0","versionStartIncluding":"0.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"finder","value":"zx"},{"lang":"en","type":"reporter","value":"zx"},{"lang":"en","type":"remediation developer","value":"Andrea Leopardi"},{"lang":"en","type":"remediation reviewer","value":"Eric Meadows-Jönsson"}],"dateAssigned":"2026-09-24T09:19:17.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory.</p>\n<p><code>Mint.HTTP2.Frame.decode_next/2</code> in <code>lib/mint/http2/frame.ex</code> compares a frame with the client's <code>max_frame_size</code> (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns <code>:more</code>, and <code>Mint.HTTP2</code> keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit.</p>\n<p>This issue affects mint: from 0.1.0 before 1.11.0.</p>"},{"base64":false,"type":"text/markdown","value":"Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory.\n\n`Mint.HTTP2.Frame.decode_next/2` in `lib/mint/http2/frame.ex` compares a frame with the client's `max_frame_size` (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns `:more`, and `Mint.HTTP2` keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit.\n\nThis issue affects mint: from 0.1.0 before 1.11.0."}],"value":"Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory.\n\nMint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the client's max_frame_size (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns :more, and Mint.HTTP2 keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit.\n\nThis issue affects mint: from 0.1.0 before 1.11.0."}],"impacts":[{"capecId":"CAPEC-130","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>A malicious or compromised HTTP/2 server can make a Mint client keep up to about 16 MiB per connection buffered, and keep it there while the connection stays open. Clients that hold many HTTP/2 connections to attacker-influenced origins, such as webhook senders, crawlers and proxies, can run out of memory.</p>"},{"base64":false,"type":"text/markdown","value":"A malicious or compromised HTTP/2 server can make a Mint client keep up to about 16 MiB per connection buffered, and keep it there while the connection stays open. Clients that hold many HTTP/2 connections to attacker-influenced origins, such as webhook senders, crawlers and proxies, can run out of memory."}],"value":"A malicious or compromised HTTP/2 server can make a Mint client keep up to about 16 MiB per connection buffered, and keep it there while the connection stays open. Clients that hold many HTTP/2 connections to attacker-influenced origins, such as webhook senders, crawlers and proxies, can run out of memory."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-28T11:15:20.657Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"GitHub Advisory","tags":["related","vendor-advisory"],"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-q95c-ccq6-j5j6"},{"name":"EEF CNA record for CVE-2026-92103","tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-92103.html"},{"name":"OSV record EEF-CVE-2026-92103","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-92103"},{"name":"Introducing commit 596ca43 in elixir-mint/mint","tags":["related"],"url":"https://github.com/elixir-mint/mint/commit/596ca4304504be68939c4929e0831557097962b8"},{"name":"Fix commit 20252ca in elixir-mint/mint","tags":["patch"],"url":"https://github.com/elixir-mint/mint/commit/20252ca85065f4d1092aed9ee4ed21841a507dfe"}],"source":{"discovery":"EXTERNAL"},"title":"Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Connect to untrusted origins over HTTP/1 only, with <code>protocols: [:http1]</code> in <code>Mint.HTTP.connect/4</code>, which never runs the HTTP/2 frame decoder. Finch and Req pools use HTTP/1 only unless <code>:http2</code> is added to their <code>protocols</code> option.</p>"},{"base64":false,"type":"text/markdown","value":"Connect to untrusted origins over HTTP/1 only, with `protocols: [:http1]` in `Mint.HTTP.connect/4`, which never runs the HTTP/2 frame decoder. Finch and Req pools use HTTP/1 only unless `:http2` is added to their `protocols` option."}],"value":"Connect to untrusted origins over HTTP/1 only, with protocols: [:http1] in Mint.HTTP.connect/4, which never runs the HTTP/2 frame decoder. Finch and Req pools use HTTP/1 only unless :http2 is added to their protocols option."}],"x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ol>\n<li>Build an HTTP/2 frame header whose 24-bit length field declares 1,000,000 bytes, above the default <code>max_frame_size</code> of 16,384.</li>\n<li>Pass the header followed by 16,384 and then 512,000 payload bytes to <code>Mint.HTTP2.Frame.decode_next/2</code> with a limit of 16,384. Each call returns <code>:more</code>, which makes <code>Mint.HTTP2</code> keep the bytes in <code>conn.buffer</code>.</li>\n<li>Pass the header with the complete 1,000,000-byte payload. Only this call returns <code>{:error, :payload_too_big}</code>.</li>\n</ol>"},{"base64":false,"type":"text/markdown","value":"1. Build an HTTP/2 frame header whose 24-bit length field declares 1,000,000 bytes, above the default `max_frame_size` of 16,384.\n2. Pass the header followed by 16,384 and then 512,000 payload bytes to `Mint.HTTP2.Frame.decode_next/2` with a limit of 16,384. Each call returns `:more`, which makes `Mint.HTTP2` keep the bytes in `conn.buffer`.\n3. Pass the header with the complete 1,000,000-byte payload. Only this call returns `{:error, :payload_too_big}`."}],"value":"* Build an HTTP/2 frame header whose 24-bit length field declares 1,000,000 bytes, above the default max_frame_size of 16,384.\n* Pass the header followed by 16,384 and then 512,000 payload bytes to Mint.HTTP2.Frame.decode_next/2 with a limit of 16,384. Each call returns :more, which makes Mint.HTTP2 keep the bytes in conn.buffer.\n* Pass the header with the complete 1,000,000-byte payload. Only this call returns {:error, :payload_too_big}."}],"x_technicalAnalysis":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>1. Late size check.</strong> <code>Mint.HTTP2.Frame.decode_next/2</code> calls <code>decode_next_raw/1</code>, whose binary pattern only matches once the full declared payload is present. The <code>max_frame_size</code> guard runs on the matched payload, so a partial frame of any declared length returns <code>:more</code>.</p>\n<p><strong>2. Unbounded buffering.</strong> On <code>:more</code>, <code>Mint.HTTP2.handle_new_data/3</code> stores the accumulated data in <code>conn.buffer</code>, and <code>maybe_concat_and_handle_new_data/2</code> prepends it to every later socket read, in both <code>stream/2</code> (active mode) and <code>recv/3</code> (passive mode). Nothing caps the buffer.</p>\n<p><strong>3. No release.</strong> Mint has no idle timer. In active mode the buffer is held until the caller closes the connection. In passive mode a <code>recv/3</code> timeout closes it, but a server that sends a byte within each timeout keeps it open. <code>max_frame_size</code> can't be set below the 16,384-byte protocol minimum, and no setting moves the check earlier.</p>"},{"base64":false,"type":"text/markdown","value":"**1. Late size check.** `Mint.HTTP2.Frame.decode_next/2` calls `decode_next_raw/1`, whose binary pattern only matches once the full declared payload is present. The `max_frame_size` guard runs on the matched payload, so a partial frame of any declared length returns `:more`.\n\n**2. Unbounded buffering.** On `:more`, `Mint.HTTP2.handle_new_data/3` stores the accumulated data in `conn.buffer`, and `maybe_concat_and_handle_new_data/2` prepends it to every later socket read, in both `stream/2` (active mode) and `recv/3` (passive mode). Nothing caps the buffer.\n\n**3. No release.** Mint has no idle timer. In active mode the buffer is held until the caller closes the connection. In passive mode a `recv/3` timeout closes it, but a server that sends a byte within each timeout keeps it open. `max_frame_size` can't be set below the 16,384-byte protocol minimum, and no setting moves the check earlier."}],"value":"1. Late size check. Mint.HTTP2.Frame.decode_next/2 calls decode_next_raw/1, whose binary pattern only matches once the full declared payload is present. The max_frame_size guard runs on the matched payload, so a partial frame of any declared length returns :more.\n\n2. Unbounded buffering. On :more, Mint.HTTP2.handle_new_data/3 stores the accumulated data in conn.buffer, and maybe_concat_and_handle_new_data/2 prepends it to every later socket read, in both stream/2 (active mode) and recv/3 (passive mode). Nothing caps the buffer.\n\n3. No release. Mint has no idle timer. In active mode the buffer is held until the caller closes the connection. In passive mode a recv/3 timeout closes it, but a server that sends a byte within each timeout keeps it open. max_frame_size can't be set below the 16,384-byte protocol minimum, and no setting moves the check earlier."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-92103","datePublished":"2026-09-28T11:15:20.657Z","dateReserved":"2026-09-15T16:00:01.513Z","dateUpdated":"2026-09-28T11:15:20.657Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"}