Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92103— Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size

Quick assessment

Affected
elixir-mint mint
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译 Elixir-Mint 中的“无限制资源分配”漏洞允许恶意 HTTP/2 服务器迫使客户端在拒绝的帧中最多持有约 16 MiB 的数据,从而消耗客户端内存。 函数(位于 )仅在完整声明的有效负载到达后,才会将帧与客户端的 (默认为 16,384 字节)进行比较。在此之前,它会返回 状态,并且 会将接收到的每个字节保留在连接缓冲区中。服务器可以声明一个长度高达 16,777,215 字节的帧,并延迟发送最后一个字节,从而在连接保持打开期间,将大约 1,024 倍于声明限制的缓冲区数据保留在内存中。由于服

CVSS 6.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92103

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size
Source: CVE Program / CVE List V5
Vulnerability Description
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory. Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the client's max_frame_size (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns :more, and Mint.HTTP2 keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit. This issue affects mint: from 0.1.0 before 1.11.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
elixir-mint mint 0.1.0 ~ 1.11.0 cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
elixir-mint mint 596ca4304504be68939c4929e0831557097962b8 ~ 20252ca85065f4d1092aed9ee4ed21841a507dfe cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-92103

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92103

请登录查看更多情报信息。

Other References for CVE-2026-92103 (5)

Same Patch Batch · elixir-mint · 2026-09-28 · 3 CVEs total

CVE-2026-91043 8.2 HIGH HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhau
CVE-2026-94194 6.3 MEDIUM Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding,

IV. Related Vulnerabilities

V. Comments for CVE-2026-92103

No comments yet


Leave a comment