{"package":"mint","ecosystem":"hex","latest_version":"1.9.3","description":"Small and composable HTTP client.","license":"Apache-2.0","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://github.com/elixir-mint/mint","repository":"https://github.com/elixir-mint/mint","downloads_weekly":419219,"health":{"score":59,"risk":"high","breakdown":{"maintenance":25,"popularity":14,"security":0,"maturity":12,"community":8,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":8,"critical":0,"high":4,"medium":3,"low":1,"details":[{"vuln_id":"CVE-2026-48861","severity":"low","summary":"CRLF injection in HTTP/1 request line via unvalidated method in Mint","affected_versions":">=0.1.0,<1.9.0|>=8db1acff30b6a9433762c18b1e1f891b8c1f74f7,<fad091454cbb7449b19edb8e1fee12ca7cf28c3a|=0.1.0|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0|=v0.1.0","fixed_version":"fad091454cbb7449b19edb8e1fee12ca7cf28c3a","source":"osv","published_at":"2026-06-02T14:15:09.015Z","in_kev":false,"epss_prob":0.00167,"epss_percentile":0.06341,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-48862","severity":"high","summary":"Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency","affected_versions":">=0.2.0,<1.9.0|>=65c6394d05a1b8aa4a7461708c3aa173e8d7a5cf,<70b97b6a5209fb288b0e04d8e657dda26c59de67|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0","fixed_version":"70b97b6a5209fb288b0e04d8e657dda26c59de67","source":"osv","published_at":"2026-06-02T14:15:10.591Z","in_kev":false,"epss_prob":0.00384,"epss_percentile":0.31113,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-49753","severity":"medium","summary":"HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing","affected_versions":">=0.1.0,<1.9.0|>=65e0e86d799a6d3b08e4372fccdd9747535e0dd6,<47e48027480228e4e32a0b4df39db497b4804921|=0.1.0|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0|=v0.1.0","fixed_version":"47e48027480228e4e32a0b4df39db497b4804921","source":"osv","published_at":"2026-06-02T14:15:17.078Z","in_kev":false,"epss_prob":0.00301,"epss_percentile":0.22454,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-49754","severity":"high","summary":"HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation","affected_versions":">=0.1.0,<1.9.0|>=596ca4304504be68939c4929e0831557097962b8,<b662d127d3028b5426c88d4c9cc7fe430491a10b|=0.1.0|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0|=v0.1.0","fixed_version":"b662d127d3028b5426c88d4c9cc7fe430491a10b","source":"osv","published_at":"2026-06-02T14:15:14.951Z","in_kev":false,"epss_prob":0.00384,"epss_percentile":0.31113,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-56810","severity":"high","summary":"mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5","affected_versions":">=0.5.0,<1.9.1|>=c575d819d39ebf7e9b77ec24584a5ffbb11c844e,<193ce714907d16e8adc4ab3c40e4f0c2f045b2a6|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=1.9.0|=v1.9.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0","fixed_version":"193ce714907d16e8adc4ab3c40e4f0c2f045b2a6","source":"osv","published_at":"2026-07-06T09:17:17.429Z","in_kev":false,"epss_prob":0.00344,"epss_percentile":0.27024,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-58229","severity":"high","summary":"Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS","affected_versions":">=0.1.0,<1.9.2|>=3e6de4bac4821b0eb4d6109e8b1f3fb6458792c8,<566d702e6f29105f77522ca7aabb9f64f2f4e333|=0.1.0|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=1.9.0|=1.9.1|=v1.9.1|=v1.9.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0|=v0.1.0","fixed_version":"566d702e6f29105f77522ca7aabb9f64f2f4e333","source":"osv","published_at":"2026-07-14T08:36:54.616Z","in_kev":false,"epss_prob":0.00305,"epss_percentile":0.2287,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-59246","severity":"medium","summary":"Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory","affected_versions":">=0.1.0,<1.9.2|>=596ca4304504be68939c4929e0831557097962b8,<5779de1666344b32aefc4354184ea07f902f73ce|=0.1.0|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=1.9.0|=1.9.1|=v1.9.1|=v1.9.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0|=v0.1.0","fixed_version":"5779de1666344b32aefc4354184ea07f902f73ce","source":"osv","published_at":"2026-07-14T08:37:04.609Z","in_kev":false,"epss_prob":0.00305,"epss_percentile":0.2287,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-59249","severity":"medium","summary":"Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections","affected_versions":">=0.1.0,<1.9.3|>=60089586ec7adc9fddb09f69a2f5919ba9ac7f33,<fc7d16538db7e40b56ed489f08683225cb0197fa|=0.1.0|=0.2.0|=0.2.1|=0.3.0|=0.4.0|=0.5.0|=1.0.0|=1.1.0|=1.2.0|=1.2.1|=1.3.0|=1.4.0|=1.4.1|=1.4.2|=1.5.0|=1.5.1|=1.5.2|=1.6.0|=1.6.1|=1.6.2|=1.7.0|=1.7.1|=1.8.0|=1.9.0|=1.9.1|=1.9.2|=v1.9.2|=v1.9.1|=v1.9.0|=v1.8.0|=v1.7.1|=v1.7.0|=v1.6.2|=v1.6.1|=v1.6.0|=v1.5.2|=v1.5.1|=v1.5.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.3.0|=v1.2.1|=v1.2.0|=v1.1.0|=v1.0.0|=v0.5.0|=v0.4.0|=v0.2.1|=v0.2.0|=v0.1.0","fixed_version":"fc7d16538db7e40b56ed489f08683225cb0197fa","source":"osv","published_at":"2026-07-16T11:39:29.939Z","in_kev":false,"epss_prob":0.00301,"epss_percentile":0.22451,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"1.9.3","total_count":27,"recent":["1.9.3","1.9.2","1.9.1","1.9.0","1.8.0","1.7.1","1.7.0","1.6.2","1.6.1","1.6.0","1.5.2","1.5.1","1.5.0","1.4.2","1.4.1","1.4.0","1.3.0","1.2.1","1.2.0","1.1.0"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":2,"first_published":"2019-02-25T16:40:28.746182Z","last_published":"2026-07-16T07:01:19.896317Z","dependencies_count":0,"dependencies":[]},"github_stats":{"stars":1417,"forks":125,"open_issues":4,"is_archived":false,"pushed_at":"2026-07-28T15:36:26Z","subscribers_count":26},"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"update_required","issues":["Moderate health score (59/100) — verify manually","4 high severity vulnerabilities"],"use_version":"1.9.3","version_hint":"Update to >= fc7d16538db7e40b56ed489f08683225cb0197fa to fix known vulnerabilities","summary":"mint@1.9.3 has vulnerabilities — update to latest"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/hex/mint","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/hex/mint","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/hex/mint","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate","hint_bulk":"You've called /api/check 34 times in 60s. Save bandwidth + tokens with POST /api/check_bulk (1 round-trip for N pkgs)."},"requested_version":null,"_cache":"hit","_response_ms":0,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":true,"bus_factor_3m":6,"active_contributors_12m":8,"primary_author_ratio":0.2857142857142857,"owner_account_age_days":2371,"is_archived":false,"stars":1411,"alerts":[]},"malicious":{"is_malicious":false},"scorecard":{"available":true,"score":4.4,"tier":"weak"},"quality":{"available":false},"version_history_summary":{"total_versions":20,"first_release_age_days":2713,"last_release_days_ago":16,"avg_days_between_releases":143,"release_velocity":"active"}}