Mint
Elixir-Mint · 14 CVEs
Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling t…
Sep 28, 2026
Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size
Sep 28, 2026
HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory
Sep 28, 2026
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pool…
Sep 19, 2026
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
Sep 4, 2026
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
Sep 4, 2026
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled conne…
Jul 16, 2026
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
Jul 14, 2026
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
Jul 14, 2026
mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5
Jul 6, 2026
HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
Jun 2, 2026
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
Jun 2, 2026
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
Jun 2, 2026
CRLF injection in HTTP/1 request line via unvalidated method in Mint
Jun 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-94194 | Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries | MEDIUM | 0.33% | Sep 28, 2026 |
| CVE-2026-92103 | Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size | MEDIUM | 0.33% | Sep 28, 2026 |
| CVE-2026-91043 | HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory | HIGH | 0.42% | Sep 28, 2026 |
| CVE-2026-82672 | Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections | MEDIUM | 0.52% | Sep 19, 2026 |
| CVE-2026-82728 | Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS | HIGH | 0.52% | Sep 4, 2026 |
| CVE-2026-82729 | Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS | MEDIUM | 0.52% | Sep 4, 2026 |
| CVE-2026-59249 | Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections | MEDIUM | 0.52% | Jul 16, 2026 |
| CVE-2026-59246 | Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory | MEDIUM | 0.50% | Jul 14, 2026 |
| CVE-2026-58229 | Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS | HIGH | 0.50% | Jul 14, 2026 |
| CVE-2026-56810 | mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5 | HIGH | 0.52% | Jul 6, 2026 |
| CVE-2026-49753 | HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing | MEDIUM | 0.52% | Jun 2, 2026 |
| CVE-2026-49754 | HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation | HIGH | 0.52% | Jun 2, 2026 |
| CVE-2026-48862 | Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency | HIGH | 0.52% | Jun 2, 2026 |
| CVE-2026-48861 | CRLF injection in HTTP/1 request line via unvalidated method in Mint | LOW | 0.22% | Jun 2, 2026 |
Showing 1 to 14 of 14 CVEs