Junglewise Threat Intelligence

CVE-2026-47067: benoitc hackney atom table exhaustion in URL parser

CVE-2026-47067 · Severity: high · CVSS 8.7 · Published 2026-05-25

Technologies: Benoitc Hackney. Vendors: Benoit Chesneau.

Executive brief

Hackney, a popular Erlang HTTP client library, is vulnerable to a denial-of-service attack that can crash the entire application environment. By providing URLs with unique or unrecognized prefixes (like "customscheme://"), an attacker can exhaust the system's internal memory table for "atoms," which are never cleaned up. This can lead to a complete service outage, requiring a full manual restart of the affected server.

Technical details

An atom table exhaustion vulnerability (CWE-770) exists in hackney's URL parser (src/hackney_url.erl). The function hackney_url:parse_url/1 extracts the scheme from a URL and converts it into a BEAM atom using binary_to_atom/2. Since BEAM atoms are not garbage-collected and have a default limit of 1,048,576, an attacker can provide a large number of unique schemes via direct request targets, webhooks, or 'Location' headers in redirect chains. Once the limit is reached, the VM terminates with a 'system_limit' error. This is fixed in version 4.0.1.

Affected products

  • benoitc hackney >= 2.0.0, < 4.0.1

Timeline

  • 2026-05-25: disclosed
  • 2026-06-26: advisory: GitHub Advisory published
  • 2026-06-26: patched: Version 4.0.1 released

References

Related threats