hackney
4.0.2
Simple HTTP client with HTTP/1.1, HTTP/2, and HTTP/3 support
Current section
12 Advisories
Jump to
Current section
12 Advisories
Unbounded memory consumption in WebSocket client in hackney
Affected Versions
Atom table exhaustion via unrecognized URL schemes in hackney
Affected Versions
CRLF injection in WebSocket upgrade request in hackney
Affected Versions
SSRF allowlist bypass via percent-encoded host in hackney
Affected Versions
HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney
Affected Versions
CR/LF injection in query parameter in hackney
Affected Versions
Unbounded body accumulation in HTTP/3 response loop in hackney
Affected Versions
SOCKS5 TLS upgrade ignores caller timeout in hackney
Affected Versions
Infinite loop in Alt-Svc header parser in hackney
Affected Versions
CRLF injection in cookie domain/path options in hackney
Affected Versions
Hackney fails to properly release HTTP connections to the pool
Affected Versions
Server-side Request Forgery (SSRF) in hackney
Affected Versions
References
- https://gist.github.com/snoopysecurity/996de09ec0cfd0ebdcfdda8ff515deb1
- https://github.com/benoitc/hackney
- https://github.com/benoitc/hackney/commit/9594ce58fabd32cd897fc28fae937694515a3d4a
- https://github.com/benoitc/hackney/releases/tag/1.21.0
- https://nvd.nist.gov/vuln/detail/CVE-2025-1211
- https://security.snyk.io/vuln/SNYK-HEX-HACKNEY-6516131
- https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
0
yesterday
15 914
last 7 days
276 454
all time
167 826 489