Vulnerability record · CVE-2026-47077 · published 25 May 2026
CVE-2026-47077: Benoitc hackney uncontrolled resource consumption vulnerability
Benoitc · Hackney
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition. This issue affects hackney: from 2.0.0 before 4.0.1.
Description
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition. This issue affects hackney: from 2.0.0 before 4.0.1.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cna.erlef.org/cves/CVE-2026-47077.html | PatchThird Party Advisory |
| https://github.com/benoitc/hackney/commit/3d25f9fea26c90609de9d64366fedfe5065413bc | Patch |
| https://github.com/benoitc/hackney/security/advisories/GHSA-jq4m-q6p2-8gwc | ExploitPatchVendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-47077 | PatchThird Party Advisory |
| https://github.com/benoitc/hackney/security/advisories/GHSA-jq4m-q6p2-8gwc | ExploitPatchVendor Advisory |
Track CVE-2026-47077 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-47077), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.