Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94194— Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries

Quick assessment

Affected
elixir-mint mint
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞名称: HTTP 请求/响应混淆(HTTP Request/Response Smuggling)——对 HTTP 请求的解释不一致 受影响组件: elixir-mint mint 漏洞描述: 在 库中存在的“HTTP 请求/响应混淆”(HTTP Request/Response Smuggling)漏洞,允许恶意的 HTTP/1 服务器使代理中间件与 Mint 客户端在复用连接(pooled connection)上产生状态不同步,从而污染后续共享该连接的请求所收到的响应。 具体而言: 1. 分块传输编码解析

CVSS 6.3 · Medium

Possible ATT&CK Techniques 2 AI

T1071 · Application Layer Protocol T1155
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94194

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries
Source: CVE Program / CVE List V5
Vulnerability Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.11.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
elixir-mint mint 0.1.0 ~ 1.11.0 cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
elixir-mint mint 60089586ec7adc9fddb09f69a2f5919ba9ac7f33 ~ 2ec8b696b5475ecbdaa87c0098957bca339e17c0 cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-94194

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94194

请登录查看更多情报信息。

Other References for CVE-2026-94194 (4)

Same Patch Batch · elixir-mint · 2026-09-28 · 3 CVEs total

CVE-2026-91043 8.2 HIGH HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhau
CVE-2026-92103 6.3 MEDIUM Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size

IV. Related Vulnerabilities

V. Comments for CVE-2026-94194

No comments yet


Leave a comment