Executive brief
Hackney, a popular HTTP client library for the Erlang ecosystem, contains a flaw when routing traffic through SOCKS5 proxies. An attacker-controlled or compromised proxy can stall the connection process indefinitely during the secure connection (TLS) setup phase. This can lead to a denial-of-service condition by exhausting system resources, such as memory and available network connections, as the application waits forever for a response that never arrives.
Technical details
The vulnerability exists in `src/hackney_socks5.erl` where the code performs a post-handshake TLS upgrade. While the SOCKS5 negotiation correctly honors user-supplied timeouts, the subsequent call to `ssl:connect/2` uses the two-argument form which defaults to an infinite timeout. An attacker-controlled SOCKS5 proxy can complete the initial handshake and then stall the TLS exchange (e.g., by not sending a ServerHello). This causes the calling Erlang process to block indefinitely, bypassing `connect_timeout` and `recv_timeout` settings. The issue is fixed in version 4.0.1 by ensuring the timeout value is correctly passed to the SSL connection call.
Affected products
- benoitc hackney >= 0.10.0, < 4.0.1
Timeline
- 2026-05-25: disclosed
- 2026-06-26: advisory
- 2026-06-26: patched