Executive brief
Hackney, a popular Erlang HTTP client library, is vulnerable to a denial-of-service attack that can crash the entire application environment. By providing URLs with unique or unrecognized prefixes (like "customscheme://"), an attacker can exhaust the system's internal memory table for "atoms," which are never cleaned up. This can lead to a complete service outage, requiring a full manual restart of the affected server.
Technical details
An atom table exhaustion vulnerability (CWE-770) exists in hackney's URL parser (src/hackney_url.erl). The function hackney_url:parse_url/1 extracts the scheme from a URL and converts it into a BEAM atom using binary_to_atom/2. Since BEAM atoms are not garbage-collected and have a default limit of 1,048,576, an attacker can provide a large number of unique schemes via direct request targets, webhooks, or 'Location' headers in redirect chains. Once the limit is reached, the VM terminates with a 'system_limit' error. This is fixed in version 4.0.1.
Affected products
- benoitc hackney >= 2.0.0, < 4.0.1
Timeline
- 2026-05-25: disclosed
- 2026-06-26: advisory: GitHub Advisory published
- 2026-06-26: patched: Version 4.0.1 released