EEF-CVE-2026-82728

    Dashboard / Vulnerabilities / EEF-CVE-2026-82728

    EEF-CVE-2026-82728

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS

    Details: ## Summary Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server data without any cap. In lib/mint/http1.ex, decode\_status\_line/4 stores the unconsumed data in conn.buffer when the status line is incomplete, and decode\_body/5 does the same for an unterminated chunk-extension line. Both wait for a CRLF the server never has to send, and conn.buffer is prepended to every subsequent socket message. The :max\_header\_list\_size budget is wired only into decode\_headers/5 and decode\_trailer\_headers/4, so neither of these states is covered by it. A malicious server, or one reached through an attacker-controlled redirect or a fetched URL, streams bytes indefinitely until the BEAM node is killed by the operating system out-of-memory handler. The chunk-extension variant is reached after a valid status line and a complete, valid header section, so an intermediary inspecting only headers sees an ordinary 200 response. This issue affects mint: from 0.1.0 before 1.10.0.

    Affected packages

    Package

    Name: mint

    Purl: pkg:hex/mint

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.1.0
    Fixed -1.10.0

    Affected versions

    0.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High