depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/hex/mint

mint

hexv1.9.3

Small and composable HTTP client.

License Apache-2.0permissive27 versions2 maintainers0 deps403,850 weekly dl
elixir-mint/mint
59
/ 100
Health
update required

[email protected] has vulnerabilities — update to latest

Update to >= fc7d16538db7e40b56ed489f08683225cb0197fa to fix known vulnerabilities

  • Moderate health score (59/100) — verify manually
  • 4 high severity vulnerabilities
Health breakdown0 – 100
25/25
maintenance
14/20
popularity
0/25
security
12/15
maturity
8/15
community
0/15
popularity_floor
Vulnerabilities
8
4 high3 medium1 low
Advisories (8)
SeverityIDSummaryFixed in
lowCVE-2026-48861CRLF injection in HTTP/1 request line via unvalidated method in Mintfad091454cbb7449b19edb8e1fee12ca7cf28c3a
highCVE-2026-48862Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency70b97b6a5209fb288b0e04d8e657dda26c59de67
mediumCVE-2026-49753HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing47e48027480228e4e32a0b4df39db497b4804921
highCVE-2026-49754HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulationb662d127d3028b5426c88d4c9cc7fe430491a10b
highCVE-2026-56810mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5193ce714907d16e8adc4ab3c40e4f0c2f045b2a6
highCVE-2026-58229Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS566d702e6f29105f77522ca7aabb9f64f2f4e333
mediumCVE-2026-59246Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory5779de1666344b32aefc4354184ea07f902f73ce
mediumCVE-2026-59249Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connectionsfc7d16538db7e40b56ed489f08683225cb0197fa
OSS Scorecard
OpenSSF security posture score
4.4/10
weak
Maintainer trust
Active maintainers (3m)
6
Contributors (12m)
8
Primary author dominance
29%
GitHub stars
1,411

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/hex/mint

First published · 2019-02-25T16:40:28.746182Z

Last updated · 2026-07-16T07:01:19.896317Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents