PT-2026-95829 · Mint · Mint

·

CVE-2026-82672

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mint versions 0.1.0 through 1.10.0
Description An inconsistent interpretation of HTTP requests, known as HTTP Request/Response Smuggling, allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection. This can lead to response-queue poisoning, where bytes from one response are attributed to subsequent requests sharing the same connection.
The issue occurs because the chunk size/1 function in Mint.HTTP1.Parse stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. Subsequently, the decode body/5 function in Mint.HTTP1 discards all bytes up to the CRLF using Parse.ignore until crlf/1. This results in the acceptance of hex digits followed by arbitrary bytes, whereas RFC 9112 only permits chunk extensions introduced by a ;. Consequently, an RFC-strict intermediary may reject a line that Mint accepts, causing a disagreement on chunk boundaries and the end of the response body.
Recommendations Update mint to version 1.10.1 or later.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82672
GHSA-RJ5M-69WP-CXQ9

Affected Products

Mint