CVE-2026-91043: CWE-770 Allocation of Resources Without Limits or Throttling in elixir-mint mint
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC 9113 section 6.5.2 defines the limit on the decoded header list. An HPACK indexed field costs one byte on the wire and decodes to a dynamic table entry of up to 4 KB, and join_cookie_headers/1 in lib/mint/http2.ex copies every cookie value of a response into one new binary. A header block under the default 256 KB wire limit therefore makes the client allocate about 1 GB for a single response, and several such responses in one delivery exhaust the memory of the process that owns the connection or of the whole VM. This issue affects mint: from 1.1.0 before 1.11.0.
AI Analysis
Technical Summary
The vulnerability in elixir-mint mint (CVE-2026-91043) stems from improper enforcement of header size limits in HTTP/2. Mint.HTTP2 applies the max_header_list_size limit only to the compressed header block size, whereas RFC 9113 section 6.5.2 mandates the limit on the decoded header list size. Because HPACK compression can expand small compressed headers into large decoded headers, a malicious server can send headers that are under the compressed size limit but expand to about 1 GB of memory allocation per response on the client side. The join_cookie_headers/1 function exacerbates this by copying all cookie values into a new binary, increasing memory usage. Multiple such responses can exhaust the memory of the connection process or the entire Erlang VM, resulting in denial of service. This affects mint versions >=1.1.0 and <1.11.0.
Potential Impact
A malicious HTTP/2 server can cause the client using affected versions of mint to allocate excessive memory, potentially exhausting process or VM memory and causing denial of service. This impacts availability of the client application relying on mint for HTTP/2 communication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider mitigating exposure by limiting connections to untrusted HTTP/2 servers or applying any recommended temporary workarounds from the vendor.
CVE-2026-91043: CWE-770 Allocation of Resources Without Limits or Throttling in elixir-mint mint
Description
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC 9113 section 6.5.2 defines the limit on the decoded header list. An HPACK indexed field costs one byte on the wire and decodes to a dynamic table entry of up to 4 KB, and join_cookie_headers/1 in lib/mint/http2.ex copies every cookie value of a response into one new binary. A header block under the default 256 KB wire limit therefore makes the client allocate about 1 GB for a single response, and several such responses in one delivery exhaust the memory of the process that owns the connection or of the whole VM. This issue affects mint: from 1.1.0 before 1.11.0.
CVSS v4.0
Score 8.2high
Affected software
elixir-mint
mint
elixir-mint
mint
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in elixir-mint mint (CVE-2026-91043) stems from improper enforcement of header size limits in HTTP/2. Mint.HTTP2 applies the max_header_list_size limit only to the compressed header block size, whereas RFC 9113 section 6.5.2 mandates the limit on the decoded header list size. Because HPACK compression can expand small compressed headers into large decoded headers, a malicious server can send headers that are under the compressed size limit but expand to about 1 GB of memory allocation per response on the client side. The join_cookie_headers/1 function exacerbates this by copying all cookie values into a new binary, increasing memory usage. Multiple such responses can exhaust the memory of the connection process or the entire Erlang VM, resulting in denial of service. This affects mint versions >=1.1.0 and <1.11.0.
Potential Impact
A malicious HTTP/2 server can cause the client using affected versions of mint to allocate excessive memory, potentially exhausting process or VM memory and causing denial of service. This impacts availability of the client application relying on mint for HTTP/2 communication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider mitigating exposure by limiting connections to untrusted HTTP/2 servers or applying any recommended temporary workarounds from the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-09-15T23:45:02.178Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aba5091f7a7c5410698ccbc
Added to database: 09/28/2026, 11:33:37 UTC
Last enriched: 09/28/2026, 11:47:43 UTC
Last updated: 09/29/2026, 01:57:22 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.