CVE-2026-47066
published 2026-05-25CVE-2026-47066: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.70%
49.5th percentile
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl does not guarantee forward progress. When parse_token/2 receives a non-token, non-whitespace, non-comma byte (e.g. !, @, =, ;), it returns the input unchanged. skip_comma/1 also returns the buffer unchanged when the first byte is not a comma. parse_entries/2 then recurses with identical data, creating a tight infinite tail-recursive loop that pins a scheduler at 100% CPU. The calling process never returns.
The entry point parse_and_cache/3 is called synchronously in the connection process on every HTTP response. A single-byte Alt-Svc: ! response header is sufficient to trigger the hang; the header is fully controlled by any HTTP origin the client connects to.
This issue affects hackney: from 2.0.0-beta.1 before 4.0.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| benoitc | hackney | >= 2.0.0 < 4.0.1 | 4.0.1 |
| benoitc | hackney | >= 2.0.0 < 4.0.1 | 4.0.1 |
| benoitc | hackney | >= 2.0.0-beta.1 < 4.0.1 | 4.0.1 |
| benoitc | hackney | >= 408e5fe20302226ea8c74dde2bcbd452d712b5b2 < e548aba1f97ffa3f4750da7b772998fb78c01894 | e548aba1f97ffa3f4750da7b772998fb78c01894 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
ghsa7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
ghsa·2026-06-26·CVSS 7.5
CVE-2026-47066 [HIGH] CWE-835 Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
### Summary
[CVE-2026-47066](https://nvd.nist.gov/vuln/detail/CVE-2026-47066) is an infinite loop (CWE-835) in hackney's Alt-Svc response header parser (`src/hackney_altsvc.erl`). When an HTTP server returns an `Alt-Svc` header whose value begins with a non-token byte (e.g. `!`, `@`, `=`, `;`), the parser enters a tight tail-recursive loop that pins an Erlang scheduler at 100% CPU and permanently hangs the calling connection process. Because the parser is invoked synchronously on every HTTP response, any attacker-controlled origin can trigger the hang with a single-byte header value.
### Details
**1. Parser dispatch**
`parse_and_cache/3` is called inside the hackney connection process on each HTTP response. It
VulDB
benoitc hackney up to 4.0.0 Alt-Svc Response Header Parser src/hackney_altsvc.erl infinite loop (EUVD-2026-31686)
vuldb·2026-05-25
CVE-2026-47066 [LOW] benoitc hackney up to 4.0.0 Alt-Svc Response Header Parser src/hackney_altsvc.erl infinite loop (EUVD-2026-31686)
A vulnerability was found in benoitc hackney up to 4.0.0. It has been declared as problematic. Affected is an unknown function of the file src/hackney_altsvc.erl of the component Alt-Svc Response Header Parser. Executing a manipulation can lead to infinite loop.
This vulnerability appears as CVE-2026-47066. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
CVEList
Infinite loop in Alt-Svc header parser in hackney
cvelistv5·2026-05-25·CVSS 8.7
CVE-2026-47066 [HIGH] CWE-835 Infinite loop in Alt-Svc header parser in hackney
Infinite loop in Alt-Svc header parser in hackney
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl does not guarantee forward progress. When parse_token/2 receives a non-token, non-whitespace, non-comma byte (e.g. !, @, =, ;), it returns the input unchanged. skip_comma/1 also returns the buffer unchanged when the first byte is not a comma. parse_entries/2 then recurses with identical data, creating a tight infinite tail-recursive loop that pins a scheduler at 100% CPU. The calling process never returns.
The entry point parse_and_cache/3 is called synchronously in the connection process on every HTTP response. A single-byte Alt-Svc: ! response header is sufficie
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cna.erlef.org/cves/CVE-2026-47066.htmlhttps://github.com/benoitc/hackney/commit/e548aba1f97ffa3f4750da7b772998fb78c01894https://github.com/benoitc/hackney/security/advisories/GHSA-6cp8-v795-jr2jhttps://osv.dev/vulnerability/EEF-CVE-2026-47066https://github.com/benoitc/hackney/security/advisories/GHSA-6cp8-v795-jr2j
2026-05-25
Published