Hackney
Vendor:
First CVE: May 25, 2026 · Active for under a year
10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hackney over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2026
59 days ago
Most Recent CVE
May 25, 2026
60 days ago
CVE Severity & Scoring
Hackney10 CVEs
30%
70%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-47071HIGH Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to | May 25, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-47066HIGH Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl do | May 25, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-47075HIGH Improper Neutralization of CRLF Sequences vulnerability in benoitc hackney allows HTTP Request Splitting. hackney does not percent-encode carriage return (\r) or line feed (\n) cha | May 25, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-47073HIGH Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory c | May 25, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-47067HIGH Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme | May 25, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-47072HIGH Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/Response Splitting. The WebSocket upgrade code in src/hackney_ws.e | May 25, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-47077HIGH Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memo | May 25, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-47076MEDIUM Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed in | May 25, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-47070MEDIUM Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl passes the original request head | May 25, 2026 | 6.1 | 24 | NO | NO |
CVE-2026-47069MEDIUM Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setcookie/3 function in src/hackney | May 25, 2026 | 5.3 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Hackney
Top CWEs
Versions
No cataloged versions.