漏洞描述翻译 Elixir-Mint 中的“无限制资源分配”漏洞允许恶意 HTTP/2 服务器迫使客户端在拒绝的帧中最多持有约 16 MiB 的数据,从而消耗客户端内存。 函数(位于 )仅在完整声明的有效负载到达后,才会将帧与客户端的 (默认为 16,384 字节)进行比较。在此之前,它会返回 状态,并且 会将接收到的每个字节保留在连接缓冲区中。服务器可以声明一个长度高达 16,777,215 字节的帧,并延迟发送最后一个字节,从而在连接保持打开期间,将大约 1,024 倍于声明限制的缓冲区数据保留在内存中。由于服
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-mint | mint | 0.1.0 ~ 1.11.0 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| elixir-mint | mint | 596ca4304504be68939c4929e0831557097962b8 ~ 20252ca85065f4d1092aed9ee4ed21841a507dfe |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91043 | 8.2 HIGH | HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhau |
| CVE-2026-94194 | 6.3 MEDIUM | Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, |
No comments yet