{"schema_version":1,"title":"Benoit Chesneau Hackney vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Benoit Chesneau Hackney: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-47074, was published on 28 May 2026.","url":"https://junglewise.ai/threats/technologies/hackney","json_url":"https://junglewise.ai/threats/technologies/hackney.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/hackney","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":11,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":11},"latest":[{"cve":"CVE-2026-47074","cvss":8.7,"epss":0.0023,"slug":"cve-2026-47074-ex-aws-ex-aws-sns-signature-bypass-in-verify-message-1","title":"ex-aws ex_aws_sns signature bypass in verify_message/1","severity":"high","exploited":false,"published_at":"2026-05-28T10:16:39.8+00:00","url":"https://junglewise.ai/threats/cve-2026-47074-ex-aws-ex-aws-sns-signature-bypass-in-verify-message-1"},{"cve":"CVE-2026-47077","cvss":7.5,"epss":0.007,"slug":"cve-2026-47077-benoitc-hackney-resource-exhaustion-in-http-3-response-loop","title":"benoitc hackney resource exhaustion in HTTP/3 response loop","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:22.837+00:00","url":"https://junglewise.ai/threats/cve-2026-47077-benoitc-hackney-resource-exhaustion-in-http-3-response-loop"},{"cve":"CVE-2026-47076","cvss":6.9,"epss":0.002,"slug":"cve-2026-47076-benoitc-hackney-ssrf-via-percent-encoded-host-in-normalize-2","title":"benoitc hackney SSRF via percent-encoded host in normalize/2","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.69+00:00","url":"https://junglewise.ai/threats/cve-2026-47076-benoitc-hackney-ssrf-via-percent-encoded-host-in-normalize-2"},{"cve":"CVE-2026-47075","cvss":6.8,"epss":0.0042,"slug":"cve-2026-47075-benoitc-hackney-http-request-splitting-via-crlf-injection-in","title":"benoitc hackney HTTP request splitting via CRLF injection in query string","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.55+00:00","url":"https://junglewise.ai/threats/cve-2026-47075-benoitc-hackney-http-request-splitting-via-crlf-injection-in"},{"cve":"CVE-2026-47073","cvss":8.7,"epss":0.0083,"slug":"cve-2026-47073-benoitc-hackney-unbounded-memory-consumption-in-websocket-client","title":"benoitc hackney unbounded memory consumption in WebSocket client","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:22.41+00:00","url":"https://junglewise.ai/threats/cve-2026-47073-benoitc-hackney-unbounded-memory-consumption-in-websocket-client"},{"cve":"CVE-2026-47072","cvss":6.9,"epss":0.0051,"slug":"cve-2026-47072-benoitc-hackney-crlf-injection-in-websocket-upgrade-request","title":"Benoitc hackney CRLF injection in WebSocket upgrade request","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.28+00:00","url":"https://junglewise.ai/threats/cve-2026-47072-benoitc-hackney-crlf-injection-in-websocket-upgrade-request"},{"cve":"CVE-2026-47071","cvss":8.2,"epss":0.007,"slug":"cve-2026-47071-benoitc-hackney-uncontrolled-resource-consumption-in-socks5-tls","title":"benoitc hackney uncontrolled resource consumption in SOCKS5 TLS upgrade","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:22.143+00:00","url":"https://junglewise.ai/threats/cve-2026-47071-benoitc-hackney-uncontrolled-resource-consumption-in-socks5-tls"},{"cve":"CVE-2026-47070","cvss":6,"epss":0.0035,"slug":"cve-2026-47070-benoitc-hackney-sensitive-data-exposure-in-http-3-redirect","title":"benoitc hackney sensitive data exposure in HTTP/3 redirect handler","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.01+00:00","url":"https://junglewise.ai/threats/cve-2026-47070-benoitc-hackney-sensitive-data-exposure-in-http-3-redirect"},{"cve":"CVE-2026-47069","cvss":2.1,"epss":0.0037,"slug":"cve-2026-47069-benoitc-hackney-crlf-injection-in-hackney-cookie","title":"benoitc hackney CRLF injection in hackney_cookie","severity":"low","exploited":false,"published_at":"2026-05-25T15:16:21.87+00:00","url":"https://junglewise.ai/threats/cve-2026-47069-benoitc-hackney-crlf-injection-in-hackney-cookie"},{"cve":"CVE-2026-47067","cvss":8.7,"epss":0.007,"slug":"cve-2026-47067-benoitc-hackney-atom-table-exhaustion-in-url-parser","title":"benoitc hackney atom table exhaustion in URL parser","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:21.74+00:00","url":"https://junglewise.ai/threats/cve-2026-47067-benoitc-hackney-atom-table-exhaustion-in-url-parser"},{"cve":"CVE-2026-47066","cvss":8.7,"epss":0.007,"slug":"cve-2026-47066-benoitc-hackney-infinite-loop-in-alt-svc-header-parser","title":"benoitc hackney infinite loop in Alt-Svc header parser","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:21.597+00:00","url":"https://junglewise.ai/threats/cve-2026-47066-benoitc-hackney-infinite-loop-in-alt-svc-header-parser"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Benoit Chesneau Hackney","slug":"hackney","vendor":{"name":"Benoit Chesneau","slug":"benoit-chesneau","url":"https://junglewise.ai/threats/vendors/benoit-chesneau"},"aliases":[],"category":"library","homepage":"https://github.com/benoitc/hackney","repo_url":"https://github.com/benoitc/hackney","description":"An HTTP client library for Erlang.","url":"https://junglewise.ai/threats/technologies/hackney"},"most_severe":[{"cve":"CVE-2026-47073","cvss":8.7,"epss":0.0083,"slug":"cve-2026-47073-benoitc-hackney-unbounded-memory-consumption-in-websocket-client","title":"benoitc hackney unbounded memory consumption in WebSocket client","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:22.41+00:00","url":"https://junglewise.ai/threats/cve-2026-47073-benoitc-hackney-unbounded-memory-consumption-in-websocket-client"},{"cve":"CVE-2026-47067","cvss":8.7,"epss":0.007,"slug":"cve-2026-47067-benoitc-hackney-atom-table-exhaustion-in-url-parser","title":"benoitc hackney atom table exhaustion in URL parser","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:21.74+00:00","url":"https://junglewise.ai/threats/cve-2026-47067-benoitc-hackney-atom-table-exhaustion-in-url-parser"},{"cve":"CVE-2026-47066","cvss":8.7,"epss":0.007,"slug":"cve-2026-47066-benoitc-hackney-infinite-loop-in-alt-svc-header-parser","title":"benoitc hackney infinite loop in Alt-Svc header parser","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:21.597+00:00","url":"https://junglewise.ai/threats/cve-2026-47066-benoitc-hackney-infinite-loop-in-alt-svc-header-parser"},{"cve":"CVE-2026-47074","cvss":8.7,"epss":0.0023,"slug":"cve-2026-47074-ex-aws-ex-aws-sns-signature-bypass-in-verify-message-1","title":"ex-aws ex_aws_sns signature bypass in verify_message/1","severity":"high","exploited":false,"published_at":"2026-05-28T10:16:39.8+00:00","url":"https://junglewise.ai/threats/cve-2026-47074-ex-aws-ex-aws-sns-signature-bypass-in-verify-message-1"},{"cve":"CVE-2026-47071","cvss":8.2,"epss":0.007,"slug":"cve-2026-47071-benoitc-hackney-uncontrolled-resource-consumption-in-socks5-tls","title":"benoitc hackney uncontrolled resource consumption in SOCKS5 TLS upgrade","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:22.143+00:00","url":"https://junglewise.ai/threats/cve-2026-47071-benoitc-hackney-uncontrolled-resource-consumption-in-socks5-tls"},{"cve":"CVE-2026-47077","cvss":7.5,"epss":0.007,"slug":"cve-2026-47077-benoitc-hackney-resource-exhaustion-in-http-3-response-loop","title":"benoitc hackney resource exhaustion in HTTP/3 response loop","severity":"high","exploited":false,"published_at":"2026-05-25T15:16:22.837+00:00","url":"https://junglewise.ai/threats/cve-2026-47077-benoitc-hackney-resource-exhaustion-in-http-3-response-loop"},{"cve":"CVE-2026-47072","cvss":6.9,"epss":0.0051,"slug":"cve-2026-47072-benoitc-hackney-crlf-injection-in-websocket-upgrade-request","title":"Benoitc hackney CRLF injection in WebSocket upgrade request","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.28+00:00","url":"https://junglewise.ai/threats/cve-2026-47072-benoitc-hackney-crlf-injection-in-websocket-upgrade-request"},{"cve":"CVE-2026-47076","cvss":6.9,"epss":0.002,"slug":"cve-2026-47076-benoitc-hackney-ssrf-via-percent-encoded-host-in-normalize-2","title":"benoitc hackney SSRF via percent-encoded host in normalize/2","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.69+00:00","url":"https://junglewise.ai/threats/cve-2026-47076-benoitc-hackney-ssrf-via-percent-encoded-host-in-normalize-2"},{"cve":"CVE-2026-47075","cvss":6.8,"epss":0.0042,"slug":"cve-2026-47075-benoitc-hackney-http-request-splitting-via-crlf-injection-in","title":"benoitc hackney HTTP request splitting via CRLF injection in query string","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.55+00:00","url":"https://junglewise.ai/threats/cve-2026-47075-benoitc-hackney-http-request-splitting-via-crlf-injection-in"},{"cve":"CVE-2026-47070","cvss":6,"epss":0.0035,"slug":"cve-2026-47070-benoitc-hackney-sensitive-data-exposure-in-http-3-redirect","title":"benoitc hackney sensitive data exposure in HTTP/3 redirect handler","severity":"medium","exploited":false,"published_at":"2026-05-25T15:16:22.01+00:00","url":"https://junglewise.ai/threats/cve-2026-47070-benoitc-hackney-sensitive-data-exposure-in-http-3-redirect"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}