🔐 CVE Alert

CVE-2026-47076

UNKNOWN 0.0

SSRF allowlist bypass via percent-encoded host in hackney

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{} record. OTP's uri_string:parse/1 and inet:parse_address/1 do not decode percent-escapes in the host, so a URL such as http://%31%32%37%2E%30%2E%30%2E%31/ is seen by a caller's allowlist validator with host %31%32%37%2E%30%2E%30%2E%31 (not an IP address), which passes the allowlist check. hackney's normalizer then decodes the host to 127.0.0.1 and opens a TCP connection to loopback. Because hackney:request/5 always calls hackney_url:normalize/2 with no opt-out, every request that takes a binary or list URL is affected. The same technique reaches cloud instance metadata services (169.254.169.254), RFC1918 networks, and any admin interface listening on localhost. This issue affects hackney: from 0.13.0 before 4.0.1.

CWE CWE-436 CWE-918
Vendor benoitc
Product hackney
Published May 25, 2026
Last Updated May 27, 2026
Stay Ahead of the Next One

Get instant alerts for benoitc hackney

Be the first to know when new unknown vulnerabilities affecting benoitc hackney are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

benoitc / hackney
0.13.0 < 4.0.1
benoitc / hackney
4d725507588942fd00efca15b86da3273656510a < 452620a92ec1da2e6b4862a049a2a4f04b42068f

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/benoitc/hackney/security/advisories/GHSA-pj7v-xfvx-wmjq cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-47076.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-47076 github.com: https://github.com/benoitc/hackney/commit/452620a92ec1da2e6b4862a049a2a4f04b42068f

Credits

Ganbagana Benoit Chesneau Jonatan Männchen / EEF