CVE Browser

CVE-2026-94194 MEDIUM

Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries

CVSS 6.3 EPSS 0.33% Sep 28, 2026
CVE-2026-92103 MEDIUM

Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size

CVSS 6.3 EPSS 0.33% Sep 28, 2026
CVE-2026-91043 HIGH

HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory

CVSS 8.2 EPSS 0.42% Sep 28, 2026
CVE-2026-82672 MEDIUM

Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections

CVSS 6.3 EPSS 0.52% Sep 19, 2026
CVE-2026-82728 HIGH

Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS

CVSS 8.2 EPSS 0.52% Sep 4, 2026
CVE-2026-82729 MEDIUM

Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS

CVSS 6.3 EPSS 0.52% Sep 4, 2026
CVE-2026-59249 MEDIUM

Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections

CVSS 6.3 EPSS 0.52% Jul 16, 2026
CVE-2026-59246 MEDIUM

Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory

CVSS 6.3 EPSS 0.50% Jul 14, 2026
CVE-2026-58229 HIGH

Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS

CVSS 8.2 EPSS 0.50% Jul 14, 2026
CVE-2026-56810 HIGH

mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5

CVSS 8.7 EPSS 0.52% Jul 6, 2026
CVE-2026-58226 HIGH

Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax

CVSS 8.7 EPSS 0.55% Jul 6, 2026
CVE-2026-49753 MEDIUM

HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing

CVSS 6.3 EPSS 0.52% Jun 2, 2026
CVE-2026-49754 HIGH

HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation

CVSS 8.2 EPSS 0.52% Jun 2, 2026
CVE-2026-48862 HIGH

Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency

CVSS 8.2 EPSS 0.52% Jun 2, 2026
CVE-2026-48861 LOW

CRLF injection in HTTP/1 request line via unvalidated method in Mint

CVSS 2.1 EPSS 0.22% Jun 2, 2026

Showing 1 to 15 CVEs · page 1