CVE-2026-47077
published 2026-05-25CVE-2026-47077: Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.70%
49.5th percentile
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition.
This issue affects hackney: from 2.0.0 before 4.0.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| benoitc | hackney | >= 0334af206d5099fdf510ed9eda18e34396f065ad < 3d25f9fea26c90609de9d64366fedfe5065413bc | 3d25f9fea26c90609de9d64366fedfe5065413bc |
| benoitc | hackney | >= 2.0.0 < 4.0.1 | 4.0.1 |
| benoitc | hackney | >= 2.0.0 < 4.0.1 | 4.0.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v4.08.2HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76v6-f83q-pxvh: Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding
ghsa_unreviewed·2026-05-26
CVE-2026-47077 [HIGH] CWE-400 GHSA-76v6-f83q-pxvh: Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition.
This issue affects hackney: from 2.0.0 before 4.0.1.
VulDB
benoitc hackney up to 4.0.0 Housekeeping Message resource consumption (EUVD-2026-31688)
vuldb·2026-05-25
CVE-2026-47077 [LOW] benoitc hackney up to 4.0.0 Housekeeping Message resource consumption (EUVD-2026-31688)
A vulnerability labeled as problematic has been found in benoitc hackney up to 4.0.0. Affected by this vulnerability is an unknown functionality of the component Housekeeping Message Handler. The manipulation results in resource consumption.
This vulnerability was named CVE-2026-47077. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
CVEList
Unbounded body accumulation in HTTP/3 response loop in hackney
cvelistv5·2026-05-25·CVSS 8.2
CVE-2026-47077 [HIGH] CWE-400 Unbounded body accumulation in HTTP/3 response loop in hackney
Unbounded body accumulation in HTTP/3 response loop in hackney
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition.
This issue affects hackney: from 2.0.0 before 4.0.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cna.erlef.org/cves/CVE-2026-47077.htmlhttps://github.com/benoitc/hackney/commit/3d25f9fea26c90609de9d64366fedfe5065413bchttps://github.com/benoitc/hackney/security/advisories/GHSA-jq4m-q6p2-8gwchttps://osv.dev/vulnerability/EEF-CVE-2026-47077https://github.com/benoitc/hackney/security/advisories/GHSA-jq4m-q6p2-8gwc
2026-05-25
Published