<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T04:12:16.751441+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324121</id>
    <title>EUVD-2026-324121</title>
    <updated>2026-10-05T04:12:16.754769+00:00</updated>
    <content>EUVD-2026-324121</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48862</id>
    <title>fkie_cve-2026-48862</title>
    <updated>2026-10-05T04:12:16.754800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding.</p>
<p>In lib/mint/http2.ex, Mint.HTTP2.decode_push_promise_headers_and_add_response/5 inserts a :reserved_remote entry into conn.streams for every promised stream ID. The neighbouring Mint.HTTP2.assert_valid_promised_stream_id/2 only verifies that the promised ID is even and not already present; client_settings.max_concurrent_streams is not consulted at promise time. The concurrency cap is only checked when the response HEADERS for the promised stream arrive, so a server that emits PUSH_PROMISE frames and withholds the matching HEADERS never trips that check.</p>
<p>HTTP/2 server push is accepted by default (client_settings.enable_push defaults to true). A single long-lived HTTP/2 connection to a hostile server lets that server pin one conn.streams entry per PUSH_PROMISE frame it sends, with no upper bound, until the client process runs out of memory.</p>
<p>This issue affects mint: from 0.2.0 before 1.9.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g586-ccqf-7x4r</id>
    <title>GHSA-g586-ccqf-7x4r — mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS</title>
    <updated>2026-10-05T04:12:16.754839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: mint</p>
<p>### Summary</p>
<p>Mint's HTTP/2 client accepts `PUSH_PROMISE` frames from any server it connects to and inserts every promised stream into a per-connection map without consulting `max_concurrent_streams`. A malicious or compromised HTTP/2 server can flood the client with `PUSH_PROMISE` frames and withhold the matching response `HEADERS`, pinning one map entry per frame indefinitely until the client process runs out of memory.</p>
<p>### Details</p>
<p>`'Elixir.Mint.HTTP2':handle_push_promise/3` in `lib/mint/http2.ex` dispatches every inbound `PUSH_PROMISE` frame to `'Elixir.Mint.HTTP2':decode_push_promise_headers_and_add_response/5`, which inserts a `:reserved_remote` entry into `conn.streams` for the promised ID. The only validation applied is that the promised ID is even and not already present; `client_settings.max_concurrent_streams` is not consulted at promise time.</p>
<p>The concurrency cap is only checked when the response `HEADERS` for the promised stream arrive. A server that emits `PUSH_PROMISE` frames and never sends the matching `HEADERS` never trips that check, and the existing tally counts only streams in open states, not `:reserved_remote` entries.</p>
<p>HTTP/2 server push is accepted by default (`client_settings.enable_push` defaults to `true`), so no application opt-in is required. A single long-lived HTTP/2 connection to a hostile server lets it pin one `conn.streams` entry per `PUSH_PROMISE` frame, with no upper bound.</p>
<p>### PoC</p>
<p>1. Stand up a raw TCP HTTP/2 server that completes the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g586-ccqf-7x4r"/>
  </entry>
</feed>
