mint is vulnerable to HTTP Response Smuggling
63
Medium Risk
Mint's HTTP/1 chunked body decoder in Mint.HTTP1.Parse.chunk_size/1 validates only the leading hex digits of a chunk size line and hands the remaining bytes to Parse.ignore_until_crlf/1, which advances over any byte until it reaches CRLF. A server can send chunk size lines with trailing bytes that Mint accepts but an RFC 9112 strict intermediary rejects, creating a chunk framing mismatch that a shared keep-alive connection can use for response smuggling against later requests. The fix adds Mint.HTTP1.Parse.chunk_extensions/1, which only accepts whitespace and well formed semicolon delimited chunk extensions before the CRLF and rejects anything else.
You are affected if you are using a version that falls within the vulnerable range and you reuse HTTP/1 connections through a proxy or intermediary that parses chunked encoding strictly.
mint is vulnerable to HTTP Response Smuggling in versions 0.0.1 - 1.10.0.
Upgrade the mint library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.