Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hackney HIGH 7.5
CVE-2026-47071

Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies …

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47072

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/Response Splitting. The WebSocket u…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47073

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imp…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47075

Improper Neutralization of CRLF Sequences vulnerability in benoitc hackney allows HTTP Request Splitting. hackney does not percent-encode carriage re…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47077

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates t…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney MEDIUM 6.5
CVE-2026-47076

Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component a…

Fix: 4.0.1+
Fix from $1,600 2026-05-25
Hackney MEDIUM 6.1
CVE-2026-47070

Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl p…

Fix: 4.0.1+
Fix from $1,600 2026-05-25
Hackney HIGH 7.5
CVE-2026-47066

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header pars…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47067

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney MEDIUM 5.3
CVE-2026-47069

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setc…

Fix: 4.0.1+
Fix from $1,600 2026-05-25