Small and composable HTTP client.
[email protected] has vulnerabilities — update to latest
Update to >= fc7d16538db7e40b56ed489f08683225cb0197fa to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| low | CVE-2026-48861 | CRLF injection in HTTP/1 request line via unvalidated method in Mint | fad091454cbb7449b19edb8e1fee12ca7cf28c3a |
| high | CVE-2026-48862 | Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency | 70b97b6a5209fb288b0e04d8e657dda26c59de67 |
| medium | CVE-2026-49753 | HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing | 47e48027480228e4e32a0b4df39db497b4804921 |
| high | CVE-2026-49754 | HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation | b662d127d3028b5426c88d4c9cc7fe430491a10b |
| high | CVE-2026-56810 | mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5 | 193ce714907d16e8adc4ab3c40e4f0c2f045b2a6 |
| high | CVE-2026-58229 | Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS | 566d702e6f29105f77522ca7aabb9f64f2f4e333 |
| medium | CVE-2026-59246 | Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory | 5779de1666344b32aefc4354184ea07f902f73ce |
| medium | CVE-2026-59249 | Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections | fc7d16538db7e40b56ed489f08683225cb0197fa |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/hex/mintFirst published · 2019-02-25T16:40:28.746182Z
Last updated · 2026-07-16T07:01:19.896317Z