Junglewise Threat Intelligence

CVE-2026-47073: benoitc hackney unbounded memory consumption in WebSocket client

CVE-2026-47073 · Severity: high · CVSS 8.7 · Published 2026-05-25

Technologies: Benoitc Hackney. Vendors: Benoit Chesneau.

Executive brief

Hackney, a popular HTTP and WebSocket client for Erlang, contains a vulnerability that allows a malicious server to crash the application using it. By sending an endless stream of data or incomplete messages, a server can force the Hackney client to consume all available system memory. This results in a denial-of-service (DoS) condition, potentially taking down the entire service or server node.

Technical details

The WebSocket client in `src/hackney_ws.erl` fails to impose upper bounds on memory consumption across three code paths: handshake response buffering, frame payload accumulation, and fragmentation buffering. In the handshake phase, `read_handshake_response/3` accumulates bytes indefinitely if the `\r\n\r\n` terminator is never sent. During frame parsing, `parse_payload/9` and `parse_active_payload/8` append incoming chunks to a buffer without validating the declared length against system limits. Finally, the `frag_buffer` can grow without bound if a server sends an endless stream of continuation frames without a final frame. An attacker-controlled WebSocket server can exploit these behaviors to cause an Out-Of-Memory (OOM) crash of the BEAM virtual machine. The vulnerability is patched in version 4.0.1.

Affected products

  • benoitc hackney >= 2.0.0, < 4.0.1

Timeline

  • 2026-05-25: disclosed
  • 2026-06-26: advisory: GitHub Advisory published
  • 2026-06-26: patched

References

Related threats