---
cve: "CVE-2026-82672"
severity: "MEDIUM"
cvss: 6.3
epss: "0.3%"
vendor: "elixir-mint"
kev: false
exploited: false
published: "2026-09-19 17:16:35"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T06:55:02+02:00"
---

# CVE-2026-82672

> 6.3 MEDIUM · 🧪 PoC

## Beschreibung

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.

Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension. Lines such as 5ZZZZZ and 5 9 are accepted as chunk size 5, and 0ZZZZ is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends.

This issue affects mint: from 0.1.0 before 1.10.1.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 9e9ae10cb6321879b8cf74dea3dd3e91d0e72f41 (Commit)
- 60089586ec7adc9fddb09f69a2f5919ba9ac7f33 (Commit)

## Referenzen

- <https://github.com/elixir-mint/mint/security/advisories/GHSA-rj5m-69wp-cxq9>
- <https://cna.erlef.org/cves/CVE-2026-82672.html>
- <https://osv.dev/vulnerability/EEF-CVE-2026-82672>
- <https://github.com/elixir-mint/mint/commit/60089586ec7adc9fddb09f69a2f5919ba9ac7f33>
- <https://github.com/elixir-mint/mint/commit/c82377838dc6e275ef40bafa664fbcdf50270c60>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-82672) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
