Executive brief
Hackney, a popular HTTP and WebSocket client for Erlang, contains a vulnerability that allows a malicious server to crash the application using it. By sending an endless stream of data or incomplete messages, a server can force the Hackney client to consume all available system memory. This results in a denial-of-service (DoS) condition, potentially taking down the entire service or server node.
Technical details
The WebSocket client in `src/hackney_ws.erl` fails to impose upper bounds on memory consumption across three code paths: handshake response buffering, frame payload accumulation, and fragmentation buffering. In the handshake phase, `read_handshake_response/3` accumulates bytes indefinitely if the `\r\n\r\n` terminator is never sent. During frame parsing, `parse_payload/9` and `parse_active_payload/8` append incoming chunks to a buffer without validating the declared length against system limits. Finally, the `frag_buffer` can grow without bound if a server sends an endless stream of continuation frames without a final frame. An attacker-controlled WebSocket server can exploit these behaviors to cause an Out-Of-Memory (OOM) crash of the BEAM virtual machine. The vulnerability is patched in version 4.0.1.
Affected products
- benoitc hackney >= 2.0.0, < 4.0.1
Timeline
- 2026-05-25: disclosed
- 2026-06-26: advisory: GitHub Advisory published
- 2026-06-26: patched