This issue affects hackney: from 2.0.0 before 4.0.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-76v6-f83q-pxvh | Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit |
Github GHSA |
GHSA-jq4m-q6p2-8gwc | Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM |
Wed, 27 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition. This issue affects hackney: from 2.0.0 before 4.0.1. | |
| Title | Unbounded body accumulation in HTTP/3 response loop in hackney | |
| First Time appeared |
Benoitc
Benoitc hackney |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:benoitc:hackney:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Benoitc
Benoitc hackney |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-05-27T15:40:53.384Z
Reserved: 2026-05-18T17:28:10.319Z
Link: CVE-2026-47077
Updated: 2026-05-26T15:47:44.255Z
Status : Analyzed
Published: 2026-05-25T15:16:22.837
Modified: 2026-06-17T10:54:18.643
Link: CVE-2026-47077
No data.
OpenCVE Enrichment
Updated: 2026-05-25T16:45:26Z
Github GHSA