chore(deps): update dependency mint to v1.11.0 #245
No reviewers
Labels
No labels
Area
Editor
Area
Micropub
Compat
Breaking
Kind
Bug
Kind
Documentation
Kind
Enhancement
Kind
Feature
Kind
Infra
Kind
Security
Kind
Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
inhji/hajur!245
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/mint-1.x-lockfile"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.10.0→1.11.0Release Notes
elixir-mint/mint (mint)
v1.11.0Compare Source
This is a minor version bump with no breaking changes. Please do upgrade from 1.10.x versions as it contains fixes for three recently-published CVEs.
Security
max_header_list_sizeon the decoded header list inMint.HTTP2. Previously, only the compressed header block was checked, letting a malicious server use HPACK-indexedcookiefields to make the client allocate about 1 GB per response. This is a fix for CVE-2026-91043 (GitHub advisory GHSA-9x8p-qrf4-jq7g).max_frame_sizebefore buffering the payload inMint.HTTP2. Previously, a malicious server could make the client buffer up to 16 MB per connection for a single frame. This is a fix for CVE-2026-92103 (GitHub advisory GHSA-q95c-ccq6-j5j6).Mint.HTTP1only whenchunkedis the final transfer coding, and close the connection after HTTP/1.0 responses withTransfer-Encoding. Previously, a malicious server could frame a response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-94194 (GitHub advisory GHSA-gvrc-75rc-7gj9).Bug Fixes and Improvements
Mint.HTTP1.stream_request_body/3for requests that aren't streaming, instead of raising.Hostheader and:authority.:modein forward-proxy mode.content-lengthheader.{:done, ref}when an HTTP/2 stream is reset withNO_ERRORbefore the end of the response.WINDOW_UPDATEframes on closed streams.v1.10.2Compare Source
v1.10.1Compare Source
Security fixes:
Mint.HTTP1. Previously, any bytes between the chunk size and the CRLF were accepted, letting a malicious server frame a chunked response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-82672 (GitHub advisory GHSA-rj5m-69wp-cxq9).Bug fixes:
CONNECTtunnel sockets open.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
242048c193to6ca94fcdc16ca94fcdc1to2f74da6bd72f74da6bd7to180e199a3echore(deps): update dependency mint to v1.10.1to chore(deps): update dependency mint to v1.11.0180e199a3eto289ffdacf6View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.