Security Advisories for mint in hex
Medium
about 1 month ago
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
hex
mint
Medium
about 1 month ago
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
hex
mint
High
about 1 month ago
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
hex
mint
High
about 2 months ago
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
hex
mint
High
about 2 months ago
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
hex
mint
Low
about 2 months ago
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
hex
mint
High
about 2 months ago
mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5
hex
mint
Medium
3 months ago
HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
hex
mint
High
3 months ago
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
hex
mint
High
3 months ago
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
hex
mint