漏洞名称: HTTP 请求/响应混淆(HTTP Request/Response Smuggling)——对 HTTP 请求的解释不一致 受影响组件: elixir-mint mint 漏洞描述: 在 库中存在的“HTTP 请求/响应混淆”(HTTP Request/Response Smuggling)漏洞,允许恶意的 HTTP/1 服务器使代理中间件与 Mint 客户端在复用连接(pooled connection)上产生状态不同步,从而污染后续共享该连接的请求所收到的响应。 具体而言: 1. 分块传输编码解析
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-mint | mint | 0.1.0 ~ 1.11.0 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| elixir-mint | mint | 60089586ec7adc9fddb09f69a2f5919ba9ac7f33 ~ 2ec8b696b5475ecbdaa87c0098957bca339e17c0 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91043 | 8.2 HIGH | HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhau |
| CVE-2026-92103 | 6.3 MEDIUM | Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size |
No comments yet