elixir-mint 库中的“无限制或限流下的资源分配”漏洞允许恶意的 HTTP/2 服务器耗尽客户端主机的内存,从而导致拒绝服务(DoS)。 Mint.HTTP2 仅在入站头块的压缩大小上强制执行客户端的 设置,而 RFC 9113 第 6.5.2 节定义的限制是针对解码后的头列表大小。HPACK 索引字段在传输中仅占一个字节,但解码后可能成为动态表中高达 4 KB 的条目。同时, 中的 函数会将响应中的每个 cookie 值复制到一个新的二进制数据(binary)中。因此,在默认的 256 KB 传输限制下,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-mint | mint | 1.1.0 ~ 1.11.0 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| elixir-mint | mint | 8e0e04680476f90f9f68db4dfeabcbe66dabfc4d ~ c7895cb022196c77ec35570c8e873a84393ff4b8 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94194 | 6.3 MEDIUM | Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, |
| CVE-2026-92103 | 6.3 MEDIUM | Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size |
No comments yet