Current section

4 Advisories

Jump to
EEF-CVE-2026-49753 CVE-2026-49753 GHSA-mjqx-c6f6-7rc2

HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing

June 02, 2026
CVSS
?
6.3 / 10.0 Medium
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Versions

>= 0.1.0 and < 1.9.0
EEF-CVE-2026-49754 CVE-2026-49754 GHSA-2p26-p43x-fhp8

HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation

June 02, 2026
CVSS
?
8.2 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.1.0 and < 1.9.0
EEF-CVE-2026-48862 CVE-2026-48862 GHSA-g586-ccqf-7x4r

Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency

June 02, 2026
CVSS
?
8.2 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 1.9.0
EEF-CVE-2026-48861 CVE-2026-48861 GHSA-2pg6-44cx-c49v

CRLF injection in HTTP/1 request line via unvalidated method in Mint

June 02, 2026
CVSS
?
2.1 / 10.0 Low
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Affected Versions

>= 0.1.0 and < 1.9.0

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 20K 40K 60K 80K

this version

0

yesterday

46 387

last 7 days

289 442

all time

59 806 656

Last Updated

Jun 02, 2026

License

Apache-2.0

Build Tools

mix

Publisher

ericmj ericmj

Links