CVE Browser
Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries
Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size
HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5
Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
CRLF injection in HTTP/1 request line via unvalidated method in Mint
Showing 1 to 15 CVEs · page 1