CVE-2026-91043 elixir-mint 资源无限制分配漏洞
影响恶意 HTTP/2 服务器可耗尽客户端内存导致拒绝服务
CVE-2026-91043 是 elixir-mint 库中 Mint.HTTP2 的资源分配不受限制漏洞。客户端仅按压缩后大小校验入站头部块,而 RFC 9113 要求限制解码后的头部列表大小,导致攻击者可构造小体积但解码后极大的头部块。
影响范围
mint 1.1.0 起至 1.11.0 之前的版本。
漏洞详情
漏洞类型为资源分配无限制/无节流(CWE-770)。HPACK 索引字段在网络上仅占 1 字节,但可解码为最大 4 KB 的动态表条目;同时 lib/mint/http2.ex 中的 join_cookie_headers/1 会把响应中所有 cookie 值复制进一个新二进制。因此默认 256 KB 线路限制下的头部块可让客户端为单个响应分配约 1 GB 内存。
利用条件与风险
利用前提是客户端连接恶意或受控的 HTTP/2 服务器;多个此类响应即可耗尽连接所属进程甚至整个 VM 的内存,造成拒绝服务。
修复建议
升级 mint 至 1.11.0 或更高版本;暂无公开的临时缓解措施信息。
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service.
Mint.HTTP2 enforces the client’s max_header_list_size setting only on the compressed size of an inbound header block, while RFC 9113 section 6.5.2 defines the limit on the decoded header list. An HPACK indexed field costs one byte on the wire and decodes to a dynamic table entry of up to 4 KB, and join_cookie_headers/1 in lib/mint/http2.ex copies every cookie value of a response into one new binary. A header block under the default 256 KB wire limit therefore makes the client allocate about 1 GB for a single response, and several such responses in one delivery exhaust the memory of the process that owns the connection or of the whole VM.
This issue affects mint: from 1.1.0 before 1.11.0.