« Volver al listado

CVE-2026-47073

Estado: AnalizadaAlta (8.7)—

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three code paths. First, read_handshake_response/3 accumulates received bytes into a growing buffer with no size cap; the per-receive timeout resets on every chunk, so a server that streams bytes without ever sending \r\n\r\n causes the buffer to grow until memory is exhausted.

Leer descripción completaMostrar menos

Second, parse_payload/9 and parse_active_payload/8 do not validate the declared frame payload length against any limit; because RFC 6455 allows payload lengths up to 2^63-1 bytes, a server that announces a very large frame and dribbles bytes causes the accumulation buffer to grow until OOM. Third, the frag_buffer field in #ws_data{} accumulates continuation frames indefinitely; a server that sends an endless stream of non-final (nofin) fragmented frames without ever sending a final (fin) frame grows frag_buffer without bound.

In all three cases the attacker only needs to control the WebSocket server the hackney client connects to, with no authentication or special client configuration required.

This issue affects hackney: from 2.0.0 before 4.0.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Red sin autenticación (AV:N, PR:N, UI:N); CWE-400 y descripción explícita de exhaustión de memoria por DoS de amplificación (server flooding con bytes)

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47073",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47073",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T15:44:41.043069Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:benoitc:hackney:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/benoitc/hackney",
          "vendor": "benoitc",
          "modules": [
            "hackney_ws"
          ],
          "product": "hackney",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "4.0.1",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:hex/hackney",
          "packageName": "hackney",
          "programFiles": [
            "src/hackney_ws.erl"
          ],
          "collectionURL": "https://repo.hex.pm",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "hackney_ws:read_handshake_response/3"
            },
            {
              "name": "hackney_ws:parse_payload/9"
            },
            {
              "name": "hackney_ws:parse_active_payload/8"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:benoitc:hackney:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/benoitc/hackney",
          "vendor": "benoitc",
          "modules": [
            "hackney_ws"
          ],
          "product": "hackney",
          "versions": [
            {
              "status": "affected",
              "version": "690cecaf236fba49526da404a5bc889a24367a3e",
              "lessThan": "ce0109e2970ace6e20ff29bae9d05c3ac22ec6dc",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/benoitc/hackney",
          "packageName": "benoitc/hackney",
          "programFiles": [
            "src/hackney_ws.erl"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "hackney_ws:read_handshake_response/3"
            },
            {
              "name": "hackney_ws:parse_payload/9"
            },
            {
              "name": "hackney_ws:parse_active_payload/8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-25T15:16:22.410",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-47073.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/benoitc/hackney/commit/ce0109e2970ace6e20ff29bae9d05c3ac22ec6dc",
      "tags": [
        "Patch"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/benoitc/hackney/security/advisories/GHSA-q8jg-fgj4-fphf",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-47073",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/benoitc/hackney/security/advisories/GHSA-q8jg-fgj4-fphf",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three code paths. First, read_handshake_response/3 accumulates received bytes into a growing buffer with no size cap; the per-receive timeout resets on every chunk, so a server that streams bytes without ever sending \\r\\n\\r\\n causes the buffer to grow until memory is exhausted. Second, parse_payload/9 and parse_active_payload/8 do not validate the declared frame payload length against any limit; because RFC 6455 allows payload lengths up to 2^63-1 bytes, a server that announces a very large frame and dribbles bytes causes the accumulation buffer to grow until OOM. Third, the frag_buffer field in #ws_data{} accumulates continuation frames indefinitely; a server that sends an endless stream of non-final (nofin) fragmented frames without ever sending a final (fin) frame grows frag_buffer without bound.\n\nIn all three cases the attacker only needs to control the WebSocket server the hackney client connects to, with no authentication or special client configuration required.\n\nThis issue affects hackney: from 2.0.0 before 4.0.1."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de asignación de recursos sin límites ni limitación en benoitc hackney permite inundación. El cliente WebSocket en src/hackney_ws.erl no impone un límite superior al consumo de memoria en tres rutas de código. Primero, read_handshake_response/3 acumula los bytes recibidos en un búfer creciente sin límite de tamaño; el tiempo de espera por recepción se reinicia en cada fragmento, por lo que un servidor que transmite bytes sin enviar nunca \\r\\n\\r\\n hace que el búfer crezca hasta que la memoria se agote. Segundo, parse_payload/9 y parse_active_payload/8 no validan la longitud de la carga útil del marco declarada contra ningún límite; debido a que RFC 6455 permite longitudes de carga útil de hasta 2^63-1 bytes, un servidor que anuncia un marco muy grande y gotea bytes hace que el búfer de acumulación crezca hasta OOM. Tercero, el campo frag_buffer en #ws_data{} acumula marcos de continuación indefinidamente; un servidor que envía un flujo interminable de marcos fragmentados no finales (nofin) sin enviar nunca un marco final (fin) hace crecer frag_buffer sin límite.\n\nEn los tres casos, el atacante solo necesita controlar el servidor WebSocket al que se conecta el cliente hackney, sin autenticación ni configuración especial del cliente requerida.\n\nEste problema afecta a hackney: desde 2.0.0 antes de 4.0.1."
    }
  ],
  "lastModified": "2026-07-24T10:10:00.197",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:benoitc:hackney:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B119C170-E9CA-4AEE-BE04-F074E70CBF82",
              "versionEndExcluding": "4.0.1",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}