CVE-2026-94194
Last modified
CVE-2026-94194 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection.
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.10.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| elixir-mint | mint | >= 0.1.0, < 1.11.0 |
| elixir-mint | mint | >= 60089586ec7adc9fddb09f69a2f5919ba9ac7f33, < 2ec8b696b5475ecbdaa87c0098957bca339e17c0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-94194?
How severe is CVE-2026-94194?
How do I fix CVE-2026-94194?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9418A flaw has been found in code-projects Employee Management S…4.3
- CVE-2026-94181An address bar spoofing issue in affected versions of Arc co…7.4
- CVE-2026-94183Arc Search for Android before version 1.12.10 does not displ…7.4
- CVE-2026-94184A stack-based buffer overflow flaw was found in fetchmail wh…8.1
- CVE-2026-94185nvm resolves a requested version or alias by treating it as …5.5
- CVE-2026-9419A vulnerability has been found in code-projects Employee Man…4.3
- CVE-2026-9420A vulnerability was found in KLiK SocialMediaWebsite 1.0. Th…6.3
- CVE-2026-9421A vulnerability was determined in KLiK SocialMediaWebsite 1.…7.3
- CVE-2026-94210A flaw has been found in Hyve5 Leantime up to 3.9.8. Affecte…3.5
- CVE-2026-94211A vulnerability has been found in Hyve5 Leantime up to 3.9.8…2.4
- CVE-2026-94213A flaw was found in the Authorization Services component of …4.9
- CVE-2026-94214A vulnerability was found in ST Engineering iDirect Evolutio…4.3
Are you affected by CVE-2026-94194?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
