CVE-2026-58229
Elixir Mint header-parsing flaw lets malicious servers cause BEAM OOM DoS.
Is CVE-2026-58229 being exploited?
Not confirmed. CVE-2026-58229 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.50% probability of exploitation in the next 30 days.
How severe is CVE-2026-58229?
CVE-2026-58229 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-58229?
Yes. A fix has been recorded for CVE-2026-58229. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-58229 affect?
CVE-2026-58229 affects mint >=0.1.0 and <1.9.2, BEAM (Elixir/Erlang) applications using Mint HTTP client. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-58229?
Upgrade to mint 1.9.2+, block/restrict untrusted HTTP endpoints and mitigate SSRF exposure.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote HTTP server can stream unlimited headers/trailers to exhaust BEAM memory, crashing the node and causing application denial of service.
Patch when possible
- affected>= 0.1.0 and < 1.9.2
- affected>= 3e6de4bac4821b0eb4d6109e8b1f3fb6458792c8 and < 566d702e6f29105f77522ca7aabb9f64f2f4e333
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.