« Volver al listado

CVE-2026-92103

Estado: AplazadaMedia (6.3)—

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory.

Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the client's max_frame_size (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns :more, and Mint.HTTP2 keeps every received byte in the connection buffer.

Leer descripción completaMostrar menos

A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit.

This issue affects mint: from 0.1.0 before 1.10.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de agotamiento de recursos (CWE-770) en servidor HTTP/2 remoto. El atacante envía declaraciones de frames grandes sin completarlas, forzando al cliente Mint a bufferizar ~16 MiB por conexión, causando negación de servicio por consumo de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-92103",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-92103",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-30T15:00:25.491334Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/elixir-mint/mint",
          "vendor": "elixir-mint",
          "modules": [
            "'Elixir.Mint.HTTP2.Frame'",
            "'Elixir.Mint.HTTP2'"
          ],
          "product": "mint",
          "versions": [
            {
              "status": "affected",
              "version": "0.1.0",
              "lessThan": "1.10.2",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:hex/mint",
          "packageName": "mint",
          "programFiles": [
            "lib/mint/http2/frame.ex",
            "lib/mint/http2.ex"
          ],
          "collectionURL": "https://repo.hex.pm",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.Mint.HTTP2.Frame':decode_next/2"
            },
            {
              "name": "'Elixir.Mint.HTTP2':stream/2"
            },
            {
              "name": "'Elixir.Mint.HTTP2':recv/3"
            },
            {
              "name": "'Elixir.Mint.HTTP2':handle_new_data/3"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/elixir-mint/mint",
          "vendor": "elixir-mint",
          "modules": [
            "'Elixir.Mint.HTTP2.Frame'",
            "'Elixir.Mint.HTTP2'"
          ],
          "product": "mint",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "20252ca85065f4d1092aed9ee4ed21841a507dfe",
                  "status": "unaffected"
                },
                {
                  "at": "44d7ce4755d0444ee415cbcca7ce4942382da4dd",
                  "status": "unaffected"
                }
              ],
              "version": "596ca4304504be68939c4929e0831557097962b8",
              "lessThan": "*",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/elixir-mint/mint",
          "packageName": "elixir-mint/mint",
          "programFiles": [
            "lib/mint/http2/frame.ex",
            "lib/mint/http2.ex"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.Mint.HTTP2.Frame':decode_next/2"
            },
            {
              "name": "'Elixir.Mint.HTTP2':stream/2"
            },
            {
              "name": "'Elixir.Mint.HTTP2':recv/3"
            },
            {
              "name": "'Elixir.Mint.HTTP2':handle_new_data/3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-28T12:17:41.973",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-92103.html",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/mint/commit/20252ca85065f4d1092aed9ee4ed21841a507dfe",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/mint/commit/44d7ce4755d0444ee415cbcca7ce4942382da4dd",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/mint/commit/596ca4304504be68939c4929e0831557097962b8",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-q95c-ccq6-j5j6",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-92103",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory.\n\nMint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the client's max_frame_size (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns :more, and Mint.HTTP2 keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit.\n\nThis issue affects mint: from 0.1.0 before 1.10.2."
    }
  ],
  "lastModified": "2026-09-30T16:19:23.600",
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}