CVE-2026-94194
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection.
message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection.
Leer descripción completaMostrar menos
For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection.
Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way.
This issue affects mint: from 0.1.0 before 1.10.2.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 6.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1565.001Stored Data Manipulationimpact75 % - Impacto secundario
T1499.004Application or System Exploitationimpact70 %
HTTP Request Smuggling permite a servidor malicioso desincronizar cliente y proxy en conexión compartida (T1190 + AV:N). Causa envenenamiento de respuestas (T1565.001) y negación de servicio (T1499.004).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-444
Referencias
- https://cna.erlef.org/cves/CVE-2026-94194.html
- https://github.com/elixir-mint/mint/commit/2ec8b696b5475ecbdaa87c0098957bca339e17c0
- https://github.com/elixir-mint/mint/commit/60089586ec7adc9fddb09f69a2f5919ba9ac7f33
- https://github.com/elixir-mint/mint/commit/8d1bbcfa566a8c1dc23d33f40d550c28250ac7b9
- https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9
- https://osv.dev/vulnerability/EEF-CVE-2026-94194
- https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-94194",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-94194",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-30T13:16:26.592339Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 6.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/elixir-mint/mint",
"vendor": "elixir-mint",
"modules": [
"'Elixir.Mint.HTTP1'"
],
"product": "mint",
"versions": [
{
"status": "affected",
"version": "0.1.0",
"lessThan": "1.10.2",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/mint",
"packageName": "mint",
"programFiles": [
"lib/mint/http1.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Mint.HTTP1':message_body/1"
},
{
"name": "'Elixir.Mint.HTTP1':stream/2"
},
{
"name": "'Elixir.Mint.HTTP1':recv/3"
}
]
},
{
"cpes": [
"cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/elixir-mint/mint",
"vendor": "elixir-mint",
"modules": [
"'Elixir.Mint.HTTP1'"
],
"product": "mint",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "2ec8b696b5475ecbdaa87c0098957bca339e17c0",
"status": "unaffected"
},
{
"at": "8d1bbcfa566a8c1dc23d33f40d550c28250ac7b9",
"status": "unaffected"
}
],
"version": "60089586ec7adc9fddb09f69a2f5919ba9ac7f33",
"lessThan": "*",
"versionType": "git"
}
],
"packageURL": "pkg:github/elixir-mint/mint",
"packageName": "elixir-mint/mint",
"programFiles": [
"lib/mint/http1.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Mint.HTTP1':message_body/1"
},
{
"name": "'Elixir.Mint.HTTP1':stream/2"
},
{
"name": "'Elixir.Mint.HTTP1':recv/3"
}
]
}
]
}
],
"published": "2026-09-28T12:17:42.220",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-94194.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-mint/mint/commit/2ec8b696b5475ecbdaa87c0098957bca339e17c0",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-mint/mint/commit/60089586ec7adc9fddb09f69a2f5919ba9ac7f33",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-mint/mint/commit/8d1bbcfa566a8c1dc23d33f40d550c28250ac7b9",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-94194",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-444"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection.\n\nmessage_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection.\n\nMint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way.\n\nThis issue affects mint: from 0.1.0 before 1.10.2."
}
],
"lastModified": "2026-09-30T14:17:43.763",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}