Vulnerability record · CVE-2026-47067 · published 25 May 2026
CVE-2026-47067: Benoitc hackney allocation without limits vulnerability
Benoitc · Hackney
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme to a permanent BEAM atom via binary_to_atom/2. BEAM atoms are never garbage-collected and the atom table defaults to a hard limit of 1,048,576 entries. An attacker who can supply URLs with attacker-chosen scheme prefixes — directly as request targets, as configured webhook URLs, or via Location headers followed during redirects — can exhaust the atom table and crash the entire BEAM VM with system_limit. This issue affects hackney: from 2.0.0 before 4.0.1.
Description
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme to a permanent BEAM atom via binary_to_atom/2. BEAM atoms are never garbage-collected and the atom table defaults to a hard limit of 1,048,576 entries. An attacker who can supply URLs with attacker-chosen scheme prefixes — directly as request targets, as configured webhook URLs, or via Location headers followed during redirects — can exhaust the atom table and crash the entire BEAM VM with system_limit. This issue affects hackney: from 2.0.0 before 4.0.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cna.erlef.org/cves/CVE-2026-47067.html | PatchThird Party Advisory |
| https://github.com/benoitc/hackney/commit/31f6f0e27e096ad88743dfded4f030a3ee74972e | Patch |
| https://github.com/benoitc/hackney/security/advisories/GHSA-9653-rcfr-5c62 | ExploitPatchVendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-47067 | PatchThird Party Advisory |
| https://github.com/benoitc/hackney/security/advisories/GHSA-9653-rcfr-5c62 | ExploitPatchVendor Advisory |
Track CVE-2026-47067 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-47067), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.