CVE-2026-48861: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') in elixir-mint mint
CVE-2026-48861 is a low-severity vulnerability in the elixir-mint Mint library that allows CRLF injection via HTTP request line manipulation. The vulnerability arises because the encode_request_line/2 function inserts user-supplied HTTP method and target directly into the request line without validating the method field. While Mint 1.7.0 added validation to the target field to reject CRLF and control characters, the method field remains unvalidated, allowing attackers to inject CRLF sequences through the method. This can lead to HTTP request splitting and request smuggling attacks. The issue affects all versions from 0.1.0 up to but not including 1.9.0.
AI Analysis
Technical Summary
The vulnerability in elixir-mint Mint (CVE-2026-48861) is an improper neutralization of CRLF sequences (CWE-93) in the HTTP request line construction. Specifically, the encode_request_line/2 function concatenates the HTTP method and target directly into the request line without validating the method for CRLF or control characters. Although Mint 1.7.0 introduced validation for the target field, the method field remains unvalidated by default, enabling attackers to inject CRLF sequences via the method parameter. This allows premature termination of the request line, injection of arbitrary headers, and smuggling of additional HTTP requests on the same TCP connection. The vulnerability affects Mint versions from 0.1.0 before 1.9.0.
Potential Impact
An attacker who can control the HTTP method parameter passed to Mint.HTTP.request/5 can exploit this vulnerability to perform HTTP request splitting and HTTP request smuggling. This may allow injection of arbitrary HTTP headers and pipelining of malicious requests over the same TCP connection. The CVSS 4.0 score is 2.1 (low severity) with local attack vector and low impact on confidentiality and integrity. No known exploits are reported in the wild.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Mint 1.7.0 introduced validation for the request target but did not validate the method field, which remains exploitable by default. Users should avoid passing untrusted input as the HTTP method to Mint.HTTP.request/5. Monitor vendor advisories for updates or patches addressing method validation. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-48861: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') in elixir-mint mint
Description
CVE-2026-48861 is a low-severity vulnerability in the elixir-mint Mint library that allows CRLF injection via HTTP request line manipulation. The vulnerability arises because the encode_request_line/2 function inserts user-supplied HTTP method and target directly into the request line without validating the method field. While Mint 1.7.0 added validation to the target field to reject CRLF and control characters, the method field remains unvalidated, allowing attackers to inject CRLF sequences through the method. This can lead to HTTP request splitting and request smuggling attacks. The issue affects all versions from 0.1.0 up to but not including 1.9.0.
CVSS v4.0
Score 2.1low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in elixir-mint Mint (CVE-2026-48861) is an improper neutralization of CRLF sequences (CWE-93) in the HTTP request line construction. Specifically, the encode_request_line/2 function concatenates the HTTP method and target directly into the request line without validating the method for CRLF or control characters. Although Mint 1.7.0 introduced validation for the target field, the method field remains unvalidated by default, enabling attackers to inject CRLF sequences via the method parameter. This allows premature termination of the request line, injection of arbitrary headers, and smuggling of additional HTTP requests on the same TCP connection. The vulnerability affects Mint versions from 0.1.0 before 1.9.0.
Potential Impact
An attacker who can control the HTTP method parameter passed to Mint.HTTP.request/5 can exploit this vulnerability to perform HTTP request splitting and HTTP request smuggling. This may allow injection of arbitrary HTTP headers and pipelining of malicious requests over the same TCP connection. The CVSS 4.0 score is 2.1 (low severity) with local attack vector and low impact on confidentiality and integrity. No known exploits are reported in the wild.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Mint 1.7.0 introduced validation for the request target but did not validate the method field, which remains exploitable by default. Users should avoid passing untrusted input as the HTTP method to Mint.HTTP.request/5. Monitor vendor advisories for updates or patches addressing method validation. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-05-25T20:44:10.697Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1efb6ee29bf47b50db3cbe
Added to database: 06/02/2026, 15:49:02 UTC
Last enriched: 07/10/2026, 09:33:58 UTC
Last updated: 07/31/2026, 20:22:05 UTC
Views: 80
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.