CVE-2026-94194 elixir-mint HTTP 请求走私漏洞
影响攻击者可污染同连接后续请求的响应,实现响应队列投毒
该漏洞属于 HTTP 请求/响应走私(HTTP Request/Response Smuggling)类型,源于 Mint 客户端对 Transfer-Encoding 分块编码的解析与 RFC 9112 不一致。恶意 HTTP/1 服务器可借此使中间代理与 Mint 客户端在池化连接上产生解析不同步,从而污染共享该连接的后续请求响应。
影响范围
受影响组件为 elixir-mint 的 mint 库,具体受影响版本范围暂无公开信息。
漏洞详情
Mint 在 lib/mint/http1.ex 的 message_body/1 中,只要 Transfer-Encoding 字段里 chunked 是第一个编码就按分块解析,而 RFC 9112 6.3 规定仅当 chunked 为最后一个编码时才使用分块框架,否则应读到连接关闭。此外 Mint 在带 Transfer-Encoding 与 Connection: keep-alive 的 HTTP/1.0 响应(含 1xx)后仍保持连接,而 RFC 9112 6.1 要求视为框架错误并关闭连接。攻击者可构造如 Transfer-Encoding: chunked, gzip 的响应,使中间代理与 Mint 对响应边界判断不同,剩余字节被当作下一请求的响应。
利用条件与风险
利用前提是客户端通过 Mint 连接恶意或被劫持的 HTTP/1 服务器,且存在遵循 RFC 的中间代理与连接复用。实战中可导致响应投毒、缓存污染或会话混淆,风险较高。
修复建议
官方修复方案暂无公开信息,建议关注 elixir-mint 项目更新;临时缓解可避免复用连接、对响应严格校验 Transfer-Encoding 与 Connection 头,或在代理层统一规范化响应框架。
Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection.
message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response’s Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection.
Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way.
This issue affects mint: from 0.1.0 before 1.11.0.