PT-2026-43068 · Hackney · Hackney
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
hackney versions 0.10.0 through 4.0.0
Description
Uncontrolled Resource Consumption in the SOCKS5 transport within
src/hackney socks5.erl allows flooding. While the caller-supplied timeout is applied during the SOCKS5 negotiation phase, the connection upgrade to TLS via the ssl:connect/2 function defaults to an infinite timeout because the Timeout variable is not forwarded. Consequently, a hostile SOCKS5 proxy that completes the handshake and then stalls or sends a partial TLS ServerHello can cause the connecting process to block indefinitely, ignoring the connect timeout or recv timeout options.Recommendations
Update hackney to version 4.0.1.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hackney