Mint

Elixir-Mint · 14 CVEs

CVE-2026-94194
MEDIUM

Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling t…

Sep 28, 2026

CVE-2026-92103
MEDIUM

Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size

Sep 28, 2026

CVE-2026-91043
HIGH

HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory

Sep 28, 2026

CVE-2026-82672
MEDIUM

Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pool…

Sep 19, 2026

CVE-2026-82728
HIGH

Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS

Sep 4, 2026

CVE-2026-82729
MEDIUM

Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS

Sep 4, 2026

CVE-2026-59249
MEDIUM

Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled conne…

Jul 16, 2026

CVE-2026-59246
MEDIUM

Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory

Jul 14, 2026

CVE-2026-58229
HIGH

Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS

Jul 14, 2026

CVE-2026-56810
HIGH

mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5

Jul 6, 2026

CVE-2026-49753
MEDIUM

HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing

Jun 2, 2026

CVE-2026-49754
HIGH

HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation

Jun 2, 2026

CVE-2026-48862
HIGH

Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency

Jun 2, 2026

CVE-2026-48861
LOW

CRLF injection in HTTP/1 request line via unvalidated method in Mint

Jun 2, 2026

Showing 1 to 14 of 14 CVEs