mint
Hex14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mintpage 1 of 1
- CVE-2026-48861LOWCVSS 2.1EG 2.1fixed in 1.9.02026-06-02
vulnerable: 0.1.0 ... 1.8.0 (23 versions)
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices the caller-s…
- CVE-2026-48862HIGHCVSS 8.2EG 8.2fixed in 1.9.02026-06-02
vulnerable: 0.2.0 ... 1.8.0 (22 versions)
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. In lib/mint/http2.ex, Mint.HTTP2.decode_push_pr…
- CVE-2026-49753MEDIUMCVSS 6.3EG 6.3fixed in 1.9.02026-06-02
vulnerable: 0.1.0 ... 1.8.0 (23 versions)
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 Content-Le…
- CVE-2026-49754HIGHCVSS 8.2EG 8.2fixed in 1.9.02026-06-02
vulnerable: 0.1.0 ... 1.8.0 (23 versions)
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). When Mint's HTTP/2 receive path observes a HE…
- CVE-2026-56810HIGHCVSS 8.7EG 8.7fixed in 1.9.12026-07-06
vulnerable: 0.5.0 ... 1.9.0 (19 versions)
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via an oversized chunked transfer-encoded response. This vulnerability is associated with program files …
- CVE-2026-58229HIGHCVSS 8.2EG 8.2fixed in 1.9.22026-07-14
vulnerable: 0.1.0 ... 1.9.1 (25 versions)
Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. The Mint.HTTP1.decode_headers/5 and Mint.HTTP1.decode_trailer_headers…
- CVE-2026-59246MEDIUMCVSS 6.3EG 6.3fixed in 1.9.22026-07-14
vulnerable: 0.1.0 ... 1.9.1 (25 versions)
Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on the client host and cause a denial of service. The Mint.HTTP2.handle_continuation/3 function in lib/mint/http2.ex …
- CVE-2026-59249MEDIUMCVSS 6.3EG 6.3fixed in 1.9.32026-07-16
vulnerable: 0.1.0 ... 1.9.2 (26 versions)
Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling re…
- CVE-2026-82672MEDIUMCVSS 6.3EG 6.3fixed in 1.10.12026-09-19
vulnerable: 0.1.0 ... 1.9.3 (28 versions)
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling…
- CVE-2026-82728HIGHCVSS 8.2EG 8.2fixed in 1.10.02026-09-04
vulnerable: 0.1.0 ... 1.9.3 (27 versions)
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server dat…
- CVE-2026-82729MEDIUMCVSS 6.3EG 6.3fixed in 1.10.02026-09-04
vulnerable: 1.9.3
Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chun…
- CVE-2026-91043HIGHCVSS 8.2EG 8.2fixed in 1.10.22026-09-28
vulnerable: 1.1.0 ... 1.9.3 (22 versions)
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_s…
- CVE-2026-92103MEDIUMCVSS 6.3EG 6.3fixed in 1.10.22026-09-28
vulnerable: 0.1.0 ... 1.9.3 (29 versions)
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory. Mint.HT…
- CVE-2026-94194MEDIUMCVSS 6.3EG 6.3fixed in 1.10.22026-09-28
vulnerable: 0.1.0 ... 1.9.3 (29 versions)
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the …
Check whether mint is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mint CVEs against the assets you own.
Book a Demo →