CVE-2026-49754: HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation

Published Jun 2, 2026
·
Updated

Summary

Mint's HTTP/2 client accumulates CONTINUATION header-block fragments into a per-connection buffer with no cap on size or frame count. A malicious or compromised HTTP/2 server can drive the client's memory to arbitrary size by streaming an endless chain of CONTINUATION frames after a HEADERS frame that omits ENDHEADERS, causing memory exhaustion and BEAM process death. A single connection to an attacker-controlled HTTP/2 endpoint is sufficient.

Details

When Mint's HTTP/2 receive path observes a HEADERS frame without the ENDHEADERS flag, 'Elixir.Mint.HTTP2':handleheaders/3 parks the unparsed header-block fragment in conn.headersbeingprocessed. Every subsequent CONTINUATION frame on that stream is then appended to the accumulator by 'Elixir.Mint.HTTP2':handlecontinuation/3.

Nothing in the receive path bounds this accumulator: there is no per-stream size cap, no CONTINUATION frame-count cap, and maxheaderlistsize is only enforced on outgoing requests (its default is :infinity, and the only enforcement helper inspects serversettings for request encoding, never inbound header blocks). Each CONTINUATION payload can be up to the peer-advertised SETTINGSMAXFRAMESIZE, so the attacker can grow headersbeingprocessed to arbitrary size at line rate.

PoC

1. Stand up a raw TCP server that speaks the HTTP/2 handshake. 2. After the client's request HEADERS arrives, respond with a HEADERS frame on stream 1 with flags = 0 (no ENDHEADERS, no ENDSTREAM) and an empty header-block fragment. 3. Stream CONTINUATION frames on stream 1, each with flags = 0 and a payload up to SETTINGSMAXFRAMESIZE. Never set ENDHEADERS. 4. The client's process memory grows linearly with the flood and the BEAM process eventually crashes with OOM.

Impact

Remote, unauthenticated denial-of-service against any process using Mint as an HTTP/2 client against an untrusted or attacker-influenced server. A single connection is sufficient to drive memory to arbitrary size and crash the BEAM process. The default Mint configuration is vulnerable; no client-side opt-in is required. Scored CVSS v4.0 8.2 (HIGH).

Workarounds

Restrict Mint to HTTP/1 on connections to untrusted servers by passing protocols: [:http1] to 'Elixir.Mint.HTTP':connect/4. This avoids the vulnerable HTTP/2 receive path entirely, at the cost of losing HTTP/2 for those connections.

Resources

Introduction commit: https://github.com/elixir-mint/mint/commit/596ca4304504be68939c4929e0831557097962b8 Patch commit: https://github.com/elixir-mint/mint/commit/b662d127d3028b5426c88d4c9cc7fe430491a10b

Other sources

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood).

When Mint's HTTP/2 receive path observes a HEADERS frame without the ENDHEADERS flag, the unparsed header-block fragment is parked in conn.headersbeingprocessed, and every subsequent CONTINUATION frame on that stream is appended to the accumulator. Nothing in the receive path caps the accumulator: there is no per-stream size limit, no CONTINUATION frame-count limit, and maxheaderlistsize is only enforced on outgoing requests, never on inbound header blocks (its default is :infinity).

A malicious or compromised HTTP/2 server can stream an endless sequence of CONTINUATION frames (each up to the peer-advertised SETTINGSMAXFRAMESIZE) and drive the client's iolist to arbitrary size, causing memory exhaustion and BEAM process death. A single connection to an attacker-controlled HTTP/2 endpoint is sufficient.

This issue affects mint: from 0.1.0 before 1.9.0.

— MITRE

Affected Software

2 affected componentsFixes available
hex/mint>=0.1.0<1.9.0
erlang/mint<1.9.0
1.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade erlang/mint to a version that resolves this vulnerability.

    Fixed in 1.9.0
  2. Upgrade

    Upgrade elixir-mint/mint to a version that resolves this vulnerability.

    Patch b662d127d3028b5426c88d4c9cc7fe430491a10b
  3. Configuration

    Restrict Mint to HTTP/1 on connections to untrusted servers by calling 'Elixir.Mint.HTTP':connect/4 with protocols: [:http1], avoiding the vulnerable HTTP/2 receive path.

    elixir-mint Mint (HTTP client connection) protocols (passed to 'Elixir.Mint.HTTP':connect/4) = [:http1]

Event History

Jun 2, 2026
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Jul 9, 2026
Advisory Published
via GitHub·11:19 PM
Data Sourced
via GitHub·11:19 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-49754?

CVE-2026-49754 has a severity rating of high, with a CVSS score of 8.2.

2

How does CVE-2026-49754 affect the Mint client?

CVE-2026-49754 allows attacker-controlled HTTP/2 servers to initiate a continuation flood that can exhaust memory in the Mint client.

3

What is the impact of CVE-2026-49754 on applications using the Mint library?

Applications using the Mint library may experience denial of service due to unbounded header-block accumulation, leading to memory exhaustion.

4

How can I mitigate the risk of CVE-2026-49754?

Mitigation for CVE-2026-49754 may involve implementing memory limits or throttling mechanisms on the Mint client to prevent resource exhaustion.

5

When was CVE-2026-49754 published?

CVE-2026-49754 was published on June 2, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203