CVE-2026-94194 Details
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.10.2.
A response smuggling vulnerability has been identified in the Elixir Mint HTTP client, specifically in versions 0.1.0 prior to 1.11.0. This vulnerability arises from an inconsistent interpretation of HTTP response headers, particularly the 'Transfer-Encoding' field. When a malicious HTTP/1 server sends a response with 'Transfer-Encoding: chunked, gzip', the Mint client incorrectly applies chunked framing, leading to a desynchronization between the client and any intermediary server (such as a proxy or load balancer) that follows RFC 9112. As a result, bytes intended for one response can be misinterpreted as part of a subsequent request, effectively poisoning the response queue.
Users can upgrade to Elixir Mint version 1.11.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9 | CISA-ADP | AdvisoryRemedyVendor |
| https://cna.erlef.org/cves/CVE-2026-94194.html | EEF | AdvisoryBundle |
| https://github.com/elixir-mint/mint/commit/2ec8b696b5475ecbdaa87c0098957bca339e17c0 | EEF | Source CodeVendor |
| https://github.com/elixir-mint/mint/commit/60089586ec7adc9fddb09f69a2f5919ba9ac7f33 | EEF | Source CodeVendor |
| https://github.com/elixir-mint/mint/commit/8d1bbcfa566a8c1dc23d33f40d550c28250ac7b9 | EEF | |
| https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9 | EEF | AdvisoryRemedyVendor |
| https://osv.dev/vulnerability/EEF-CVE-2026-94194 | EEF | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | EEF |
Affected Products
| Product | Versions |
|---|---|
| elixir-mint mint | >= 0.1.0, < 1.11.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | CVE Modified | EEF |
| Sep 28, 2026 | New CVE Received | EEF |
Volerion