chore(deps): update dependency mint to v1.11.0 #245

Open
renovate wants to merge 1 commit from renovate/mint-1.x-lockfile into main
Collaborator

This PR contains the following updates:

Package Type Update Change
mint (source) prod minor 1.10.0 → 1.11.0

Release Notes

elixir-mint/mint (mint)

v1.11.0

Compare Source

This is a minor version bump with no breaking changes. Please do upgrade from 1.10.x versions as it contains fixes for three recently-published CVEs.

Security
  • Enforce max_header_list_size on the decoded header list in Mint.HTTP2. Previously, only the compressed header block was checked, letting a malicious server use HPACK-indexed cookie fields to make the client allocate about 1 GB per response. This is a fix for CVE-2026-91043 (GitHub advisory GHSA-9x8p-qrf4-jq7g).
  • Check the HTTP/2 frame length against max_frame_size before buffering the payload in Mint.HTTP2. Previously, a malicious server could make the client buffer up to 16 MB per connection for a single frame. This is a fix for CVE-2026-92103 (GitHub advisory GHSA-q95c-ccq6-j5j6).
  • Use chunked framing in Mint.HTTP1 only when chunked is the final transfer coding, and close the connection after HTTP/1.0 responses with Transfer-Encoding. Previously, a malicious server could frame a response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-94194 (GitHub advisory GHSA-gvrc-75rc-7gj9).
Bug Fixes and Improvements
  • Don't close the connection on a receive timeout.
  • Reject invalid HTTP/1 status lines and header fields, and unfold obsolete line folding.
  • Apply the line size limit to complete HTTP/1 status and chunk-size lines.
  • Fail HTTP/1 requests pipelined behind a response that closes the connection.
  • Return errors from Mint.HTTP1.stream_request_body/3 for requests that aren't streaming, instead of raising.
  • Return responses before an error in the order they were parsed.
  • Bracket IPv6 literal hostnames in the Host header and :authority.
  • Keep the caller's :mode in forward-proxy mode.
  • Reject HTTP/2 responses with invalid header fields, pseudo-headers or connection-specific headers.
  • Reject HTTP/2 response bodies that don't match the content-length header.
  • Reject invalid HTTP/2 DATA, padding, SETTINGS and extension frames.
  • Return an error instead of {:done, ref} when an HTTP/2 stream is reset with NO_ERROR before the end of the response.
  • Validate and track HTTP/2 server push streams.
  • Apply the acknowledged HTTP/2 header table size to the decoding table.
  • Keep the HTTP/2 receive window in sync when the window shrinks.
  • Ignore HTTP/2 WINDOW_UPDATE frames on closed streams.

v1.10.2

Compare Source

v1.10.1

Compare Source

Security fixes:

  • Validate chunk extensions in HTTP/1 chunked responses in Mint.HTTP1. Previously, any bytes between the chunk size and the CRLF were accepted, letting a malicious server frame a chunked response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-82672 (GitHub advisory GHSA-rj5m-69wp-cxq9).

Bug fixes:

  • Close TCP sockets on errors in HTTP/1.
  • Keep HTTP/1.0 CONNECT tunnel sockets open.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [mint](https://hex.pm/packages/mint) ([source](https://github.com/elixir-mint/mint)) | prod | minor | `1.10.0` → `1.11.0` | --- ### Release Notes <details> <summary>elixir-mint/mint (mint)</summary> ### [`v1.11.0`](https://github.com/elixir-mint/mint/blob/HEAD/CHANGELOG.md#v1110) [Compare Source](https://github.com/elixir-mint/mint/compare/v1.10.2...v1.11.0) This is a minor version bump with *no breaking changes*. Please do upgrade from 1.10.x versions as it contains fixes for three recently-published CVEs. ##### Security - Enforce `max_header_list_size` on the decoded header list in `Mint.HTTP2`. Previously, only the compressed header block was checked, letting a malicious server use HPACK-indexed `cookie` fields to make the client allocate about 1 GB per response. This is a fix for **CVE-2026-91043** (GitHub advisory [GHSA-9x8p-qrf4-jq7g](https://github.com/elixir-mint/mint/security/advisories/GHSA-9x8p-qrf4-jq7g)). - Check the HTTP/2 frame length against `max_frame_size` before buffering the payload in `Mint.HTTP2`. Previously, a malicious server could make the client buffer up to 16 MB per connection for a single frame. This is a fix for **CVE-2026-92103** (GitHub advisory [GHSA-q95c-ccq6-j5j6](https://github.com/elixir-mint/mint/security/advisories/GHSA-q95c-ccq6-j5j6)). - Use chunked framing in `Mint.HTTP1` only when `chunked` is the final transfer coding, and close the connection after HTTP/1.0 responses with `Transfer-Encoding`. Previously, a malicious server could frame a response differently from a strict intermediary on a shared connection. This is a fix for **CVE-2026-94194** (GitHub advisory [GHSA-gvrc-75rc-7gj9](https://github.com/elixir-mint/mint/security/advisories/GHSA-gvrc-75rc-7gj9)). ##### Bug Fixes and Improvements - Don't close the connection on a receive timeout. - Reject invalid HTTP/1 status lines and header fields, and unfold obsolete line folding. - Apply the line size limit to complete HTTP/1 status and chunk-size lines. - Fail HTTP/1 requests pipelined behind a response that closes the connection. - Return errors from `Mint.HTTP1.stream_request_body/3` for requests that aren't streaming, instead of raising. - Return responses before an error in the order they were parsed. - Bracket IPv6 literal hostnames in the `Host` header and `:authority`. - Keep the caller's `:mode` in forward-proxy mode. - Reject HTTP/2 responses with invalid header fields, pseudo-headers or connection-specific headers. - Reject HTTP/2 response bodies that don't match the `content-length` header. - Reject invalid HTTP/2 DATA, padding, SETTINGS and extension frames. - Return an error instead of `{:done, ref}` when an HTTP/2 stream is reset with `NO_ERROR` before the end of the response. - Validate and track HTTP/2 server push streams. - Apply the acknowledged HTTP/2 header table size to the decoding table. - Keep the HTTP/2 receive window in sync when the window shrinks. - Ignore HTTP/2 `WINDOW_UPDATE` frames on closed streams. ### [`v1.10.2`](https://github.com/elixir-mint/mint/compare/v1.10.1...v1.10.2) [Compare Source](https://github.com/elixir-mint/mint/compare/v1.10.1...v1.10.2) ### [`v1.10.1`](https://github.com/elixir-mint/mint/blob/HEAD/CHANGELOG.md#v1101) [Compare Source](https://github.com/elixir-mint/mint/compare/v1.10.0...v1.10.1) **Security fixes**: - Validate chunk extensions in HTTP/1 chunked responses in `Mint.HTTP1`. Previously, any bytes between the chunk size and the CRLF were accepted, letting a malicious server frame a chunked response differently from a strict intermediary on a shared connection. This is a fix for **CVE-2026-82672** (GitHub advisory [GHSA-rj5m-69wp-cxq9](https://github.com/elixir-mint/mint/security/advisories/GHSA-rj5m-69wp-cxq9)). Bug fixes: - Close TCP sockets on errors in HTTP/1. - Keep HTTP/1.0 `CONNECT` tunnel sockets open. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
renovate force-pushed renovate/mint-1.x-lockfile from 242048c193 to 6ca94fcdc1 2026-09-21 12:00:34 +02:00 Compare
renovate force-pushed renovate/mint-1.x-lockfile from 6ca94fcdc1 to 2f74da6bd7 2026-09-24 12:00:35 +02:00 Compare
renovate force-pushed renovate/mint-1.x-lockfile from 2f74da6bd7 to 180e199a3e 2026-09-28 12:01:41 +02:00 Compare
renovate changed title from chore(deps): update dependency mint to v1.10.1 to chore(deps): update dependency mint to v1.11.0 2026-09-28 12:01:44 +02:00
renovate force-pushed renovate/mint-1.x-lockfile from 180e199a3e to 289ffdacf6 2026-09-29 12:01:41 +02:00 Compare
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/mint-1.x-lockfile:renovate/mint-1.x-lockfile
git switch renovate/mint-1.x-lockfile
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
inhji/hajur!245
No description provided.