CVE-2026-49754: HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
Summary
Mint's HTTP/2 client accumulates CONTINUATION header-block fragments into a per-connection buffer with no cap on size or frame count. A malicious or compromised HTTP/2 server can drive the client's memory to arbitrary size by streaming an endless chain of CONTINUATION frames after a HEADERS frame that omits ENDHEADERS, causing memory exhaustion and BEAM process death. A single connection to an attacker-controlled HTTP/2 endpoint is sufficient.
Details
When Mint's HTTP/2 receive path observes a HEADERS frame without the ENDHEADERS flag, 'Elixir.Mint.HTTP2':handleheaders/3 parks the unparsed header-block fragment in conn.headersbeingprocessed. Every subsequent CONTINUATION frame on that stream is then appended to the accumulator by 'Elixir.Mint.HTTP2':handlecontinuation/3.
Nothing in the receive path bounds this accumulator: there is no per-stream size cap, no CONTINUATION frame-count cap, and maxheaderlistsize is only enforced on outgoing requests (its default is :infinity, and the only enforcement helper inspects serversettings for request encoding, never inbound header blocks). Each CONTINUATION payload can be up to the peer-advertised SETTINGSMAXFRAMESIZE, so the attacker can grow headersbeingprocessed to arbitrary size at line rate.
PoC
1. Stand up a raw TCP server that speaks the HTTP/2 handshake. 2. After the client's request HEADERS arrives, respond with a HEADERS frame on stream 1 with flags = 0 (no ENDHEADERS, no ENDSTREAM) and an empty header-block fragment. 3. Stream CONTINUATION frames on stream 1, each with flags = 0 and a payload up to SETTINGSMAXFRAMESIZE. Never set ENDHEADERS. 4. The client's process memory grows linearly with the flood and the BEAM process eventually crashes with OOM.
Impact
Remote, unauthenticated denial-of-service against any process using Mint as an HTTP/2 client against an untrusted or attacker-influenced server. A single connection is sufficient to drive memory to arbitrary size and crash the BEAM process. The default Mint configuration is vulnerable; no client-side opt-in is required. Scored CVSS v4.0 8.2 (HIGH).
Workarounds
Restrict Mint to HTTP/1 on connections to untrusted servers by passing protocols: [:http1] to 'Elixir.Mint.HTTP':connect/4. This avoids the vulnerable HTTP/2 receive path entirely, at the cost of losing HTTP/2 for those connections.
Resources
Introduction commit: https://github.com/elixir-mint/mint/commit/596ca4304504be68939c4929e0831557097962b8 Patch commit: https://github.com/elixir-mint/mint/commit/b662d127d3028b5426c88d4c9cc7fe430491a10b
Other sources
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood).
When Mint's HTTP/2 receive path observes a HEADERS frame without the ENDHEADERS flag, the unparsed header-block fragment is parked in conn.headersbeingprocessed, and every subsequent CONTINUATION frame on that stream is appended to the accumulator. Nothing in the receive path caps the accumulator: there is no per-stream size limit, no CONTINUATION frame-count limit, and maxheaderlistsize is only enforced on outgoing requests, never on inbound header blocks (its default is :infinity).
A malicious or compromised HTTP/2 server can stream an endless sequence of CONTINUATION frames (each up to the peer-advertised SETTINGSMAXFRAMESIZE) and drive the client's iolist to arbitrary size, causing memory exhaustion and BEAM process death. A single connection to an attacker-controlled HTTP/2 endpoint is sufficient.
This issue affects mint: from 0.1.0 before 1.9.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
erlang/mintto a version that resolves this vulnerability.Fixed in 1.9.0 - Upgrade
Upgrade
elixir-mint/mintto a version that resolves this vulnerability.Patch b662d127d3028b5426c88d4c9cc7fe430491a10b - Configuration
Restrict Mint to HTTP/1 on connections to untrusted servers by calling 'Elixir.Mint.HTTP':connect/4 with protocols: [:http1], avoiding the vulnerable HTTP/2 receive path.
elixir-mint Mint (HTTP client connection) protocols (passed to 'Elixir.Mint.HTTP':connect/4) = [:http1]
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49754?
CVE-2026-49754 has a severity rating of high, with a CVSS score of 8.2.
How does CVE-2026-49754 affect the Mint client?
CVE-2026-49754 allows attacker-controlled HTTP/2 servers to initiate a continuation flood that can exhaust memory in the Mint client.
What is the impact of CVE-2026-49754 on applications using the Mint library?
Applications using the Mint library may experience denial of service due to unbounded header-block accumulation, leading to memory exhaustion.
How can I mitigate the risk of CVE-2026-49754?
Mitigation for CVE-2026-49754 may involve implementing memory limits or throttling mechanisms on the Mint client to prevent resource exhaustion.
When was CVE-2026-49754 published?
CVE-2026-49754 was published on June 2, 2026.