mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
🔗 CVE IDs covered (1)
📋 Description
Summary
Mint's HTTP/2 client accepts PUSH_PROMISE frames from any server it connects to and inserts every promised stream into a per-connection map without consulting max_concurrent_streams. A malicious or compromised HTTP/2 server can flood the client with PUSH_PROMISE frames and withhold the matching response HEADERS, pinning one map entry per frame indefinitely until the client process runs out of memory.
Details
'Elixir.Mint.HTTP2':handle_push_promise/3 in lib/mint/http2.ex dispatches every inbound PUSH_PROMISE frame to 'Elixir.Mint.HTTP2':decode_push_promise_headers_and_add_response/5, which inserts a :reserved_remote entry into conn.streams for the promised ID. The only validation applied is that the promised ID is even and not already present; client_settings.max_concurrent_streams is not consulted at promise time.
The concurrency cap is only checked when the response HEADERS for the promised stream arrive. A server that emits PUSH_PROMISE frames and never sends the matching HEADERS never trips that check, and the existing tally counts only streams in open states, not :reserved_remote entries.
HTTP/2 server push is accepted by default (client_settings.enable_push defaults to true), so no application opt-in is required. A single long-lived HTTP/2 connection to a hostile server lets it pin one conn.streams entry per PUSH_PROMISE frame, with no upper bound.
PoC
- Stand up a raw TCP HTTP/2 server that completes the handshake and ACKs the client's
SETTINGS. - Wait for the client's request
HEADERSand capture its odd stream ID. - Send a flood of
PUSH_PROMISEframes (flags = END_HEADERS) associated with the captured stream, each promising a fresh even stream ID and carrying a minimal HPACK-encoded header block. - Never send the matching response
HEADERSfor any of the promised IDs. - The client's
conn.streamsmap grows by one entry perPUSH_PROMISEframe (~148 bytes/entry); memory grows linearly and the BEAM process eventually crashes with OOM.
Impact
Remote, unauthenticated denial-of-service against any process using Mint as an HTTP/2 client against an untrusted or attacker-influenced server. Server push is on by default, so no application code change can prevent it short of disabling push or upgrading. Affected populations include outbound HTTP/2 clients in web backends, webhook delivery systems, scrapers, federated and proxy components, and any service that follows redirects to third-party HTTP/2 origins.
Workarounds
Disable HTTP/2 server push on connections to untrusted servers by passing client_settings: [enable_push: false] to 'Elixir.Mint.HTTP':connect/4. Mint will then reject any inbound PUSH_PROMISE frame with a PROTOCOL_ERROR before the vulnerable code path is reached.
Resources
- Introduction commit: https://github.com/elixir-mint/mint/commit/65c6394d05a1b8aa4a7461708c3aa173e8d7a5cf
- Patch commit: https://github.com/elixir-mint/mint/commit/70b97b6a5209fb288b0e04d8e657dda26c59de67
🎯 Affected products1
- erlang/mint:>= 0.2.0, < 1.9.0
🔗 References (6)
- https://github.com/elixir-mint/mint/security/advisories/GHSA-g586-ccqf-7x4r
- https://nvd.nist.gov/vuln/detail/CVE-2026-48862
- https://github.com/elixir-mint/mint/commit/70b97b6a5209fb288b0e04d8e657dda26c59de67
- https://cna.erlef.org/cves/CVE-2026-48862.html
- https://osv.dev/vulnerability/EEF-CVE-2026-48862
- https://github.com/advisories/GHSA-g586-ccqf-7x4r