Intel

AIKIDO-2026-275964

mint is vulnerable to HTTP Response Smuggling

HTTP Response SmugglingCVE-2026-82672 Published 5 days ago

63

Medium Risk

This Affects:

ELIXIRmint
0.0.1 - 1.10.0
Fixed in 1.10.1
Are you affected? Scan for Free

TL;DR

Mint's HTTP/1 chunked body decoder in Mint.HTTP1.Parse.chunk_size/1 validates only the leading hex digits of a chunk size line and hands the remaining bytes to Parse.ignore_until_crlf/1, which advances over any byte until it reaches CRLF. A server can send chunk size lines with trailing bytes that Mint accepts but an RFC 9112 strict intermediary rejects, creating a chunk framing mismatch that a shared keep-alive connection can use for response smuggling against later requests. The fix adds Mint.HTTP1.Parse.chunk_extensions/1, which only accepts whitespace and well formed semicolon delimited chunk extensions before the CRLF and rejects anything else.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you reuse HTTP/1 connections through a proxy or intermediary that parses chunked encoding strictly.

Background info

mint is vulnerable to HTTP Response Smuggling in versions 0.0.1 - 1.10.0.

How to fix this

Upgrade the mint library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform