{"id":"CVE-2026-48861","aliases":["GHSA-2pg6-44cx-c49v"],"title":"mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`","summary":"mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`","severity":"low","cwe":["CWE-93"],"vendor":"mint","product":"mint","ecosystem":"erlang","affected":["mint < 1.9.0"],"patched":["mint 1.9.0"],"published":"2026-07-09","updated":"2026-07-09","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-2pg6-44cx-c49v","references":[{"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-2pg6-44cx-c49v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48861"},{"url":"https://github.com/elixir-mint/mint/commit/fad091454cbb7449b19edb8e1fee12ca7cf28c3a"},{"url":"https://cna.erlef.org/cves/CVE-2026-48861.html"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-48861"},{"url":"https://github.com/advisories/GHSA-2pg6-44cx-c49v"}],"tags":["ghsa","erlang"],"epss":0.00167,"epssPercentile":0.06352,"ingestedAt":"2026-07-09T23:53:27.244Z","slug":"CVE-2026-48861","body":"## Overview\n\n### Summary\n\nMint's HTTP/1 request encoder splices the caller-supplied `method` and `target` directly into the request line without character validation. An application that forwards attacker-controlled input as the HTTP method or the target to `Mint.HTTP.request/5` is exposed to request-line CRLF injection, allowing the attacker to terminate the request line early, inject arbitrary headers, and pipeline a fully attacker-chosen second request onto the same TCP connection.\n\n### Details\n\n`encode_request_line/2` in `lib/mint/http1/request.ex` writes `method` and `target` to the wire verbatim. `encode_headers/1` validates header names and values, but there is no equivalent `validate_method!/1`.\n\nMint 1.7.0 added `validate_request_target/2`, which rejects CRLF and other control characters in `target` by default and closes the path/query vector. The `method` field remains unvalidated, so a CRLF-bearing method such as `\"GET / HTTP/1.1\\r\\nX-Smuggled: 1\\r\\nGET /admin\"` is accepted and written to the socket as-is. Bytes after the first `\\r\\n` are interpreted by the peer as an injected header, or, with a second `\\r\\n`, as an additional pipelined request.\n\n### PoC\n\n1. Stand up a Mint-using gateway/proxy that calls `Mint.HTTP.request(conn, method, \"/\", [], nil)` with `method` taken from caller input.\n2. Send a request whose forwarded method is `\"GET / HTTP/1.1\\r\\nX-Smuggled-Header: pwned\\r\\nGET /admin/delete-everything\"`.\n3. Observe the bytes received by the upstream server: the smuggled header line and the second request line appear verbatim in the outbound stream.\n\n### Impact\n\nCRLF injection / HTTP request smuggling in the HTTP/1 client encoder, exploitable under default configuration whenever an application passes caller-influenced input as the HTTP method. An attacker who controls the method can inject arbitrary outbound headers (forged `Host`, `Authorization`, cache-poisoning headers) and smuggle additional, fully attacker-chosen requests to the upstream server over the same connection, potentially reaching endpoints the legitimate caller never intended to invoke.\n\n## Resources\n\n* Introduction commit: https://github.com/elixir-mint/mint/commit/8db1acff30b6a9433762c18b1e1f891b8c1f74f7\n* Patch commit: https://github.com/elixir-mint/mint/commit/fad091454cbb7449b19edb8e1fee12ca7cf28c3a\n\n## Affected packages\n\n- `mint < 1.9.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `mint 1.9.0`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}