Eric Meadows-Jönsson
9 exploits
Active since Feb 2026
CRLF injection in HTTP/1 request line via unvalidated method in Mint
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
Unbounded exponent in decimal enables unauthenticated DoS
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVSS 5.9
hexpm < 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 - Denial of Service via Oversized Package Upload
CVSS 6.5
hexpm hexpm/hexpm - Privilege Escalation
CVSS 5.3
hex_core < 0.12.1, hex < 2.3.2, rebar3 < 3.27.0 - Resource Consumption & Untrusted Data Deserialization
CVSS 7.5