Junglewise Threat Intelligence

CVE-2026-47075: benoitc hackney HTTP request splitting via CRLF injection in query string

CVE-2026-47075 · Severity: medium · CVSS 6.8 · Published 2026-05-25

Technologies: Benoitc Hackney.

Executive brief

Hackney, a popular HTTP client library for Erlang, contains a vulnerability that allows attackers to inject malicious data into web requests. By including special characters in a URL, an attacker can trick the library into sending unauthorized commands or headers to a server. This could lead to unauthorized access to data or the ability to bypass security controls on web proxies and servers.

Technical details

The `hackney_url:make_url/3` function in `src/hackney_url.erl` fails to percent-encode `\r` or `\n` characters in the query component of a URL. Because these characters are passed verbatim into the HTTP/1.1 request line, an attacker can terminate the request line prematurely and inject arbitrary HTTP headers or split the request into multiple distinct requests. This CRLF injection vulnerability can be exploited if an application passes attacker-controlled URL components to Hackney without prior sanitization. The issue is resolved in version 4.0.1.

Affected products

  • benoitc hackney < 4.0.1

Timeline

  • 2026-05-25: disclosed
  • 2026-06-26: advisory: GitHub Advisory published

References