mint is vulnerable to Allocation of Resources Without Limits or Throttling
63
Medium Risk
Mint's HTTP/2 client accumulates header block fragments from CONTINUATION frames and only checks the running byte total against the advertised maximum header list size. Zero length CONTINUATION frames add no bytes, so an untrusted server can send an unbounded stream of them after a headers frame that omits the END_HEADERS flag, growing memory without hitting the size check until the client process is exhausted and terminated. The fix accounts for zero length frames so the accumulation cannot grow without bound.
You are affected if you are using a version that falls within the vulnerable range and use Mint as an HTTP/2 client against servers you do not fully control.
mint is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.1.0 - 1.9.1.
Upgrade the mint library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.