πŸ” CVE Alert

CVE-2026-47067

UNKNOWN 0.0

Atom table exhaustion via unrecognized URL schemes in hackney

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme to a permanent BEAM atom via binary_to_atom/2. BEAM atoms are never garbage-collected and the atom table defaults to a hard limit of 1,048,576 entries. An attacker who can supply URLs with attacker-chosen scheme prefixes β€” directly as request targets, as configured webhook URLs, or via Location headers followed during redirects β€” can exhaust the atom table and crash the entire BEAM VM with system_limit. This issue affects hackney: from 2.0.0 before 4.0.1.

CWE CWE-770
Vendor benoitc
Product hackney
Published May 25, 2026
Last Updated May 27, 2026
Stay Ahead of the Next One

Get instant alerts for benoitc hackney

Be the first to know when new unknown vulnerabilities affecting benoitc hackney are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

benoitc / hackney
2.0.0 < 4.0.1
benoitc / hackney
d9713695c0d99855d12c73fd8a0b4be0543950c4 < 31f6f0e27e096ad88743dfded4f030a3ee74972e

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/benoitc/hackney/security/advisories/GHSA-9653-rcfr-5c62 cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-47067.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-47067 github.com: https://github.com/benoitc/hackney/commit/31f6f0e27e096ad88743dfded4f030a3ee74972e

Credits

Peter Ullrich Benoit Chesneau Jonatan MΓ€nnchen / EEF