PT-2026-43068 · Hackney · Hackney

·

CVE-2026-47071

·

Published

2026-05-25

·

Updated

2026-07-24

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions hackney versions 0.10.0 through 4.0.0
Description Uncontrolled Resource Consumption in the SOCKS5 transport within src/hackney socks5.erl allows flooding. While the caller-supplied timeout is applied during the SOCKS5 negotiation phase, the connection upgrade to TLS via the ssl:connect/2 function defaults to an infinite timeout because the Timeout variable is not forwarded. Consequently, a hostile SOCKS5 proxy that completes the handshake and then stalls or sends a partial TLS ServerHello can cause the connecting process to block indefinitely, ignoring the connect timeout or recv timeout options.
Recommendations Update hackney to version 4.0.1.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47071
GHSA-GP9C-PM5M-5CXR

Affected Products

Hackney