GHSA-76v6-f83q-pxvh

Suggest an improvement
Source
https://github.com/advisories/GHSA-76v6-f83q-pxvh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-76v6-f83q-pxvh/GHSA-76v6-f83q-pxvh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-76v6-f83q-pxvh
Withdrawn
2026-06-30T17:15:56Z
Published
2026-05-26T13:30:46Z
Modified
2026-09-10T03:50:46Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jq4m-q6p2-8gwc. This link is maintained to preserve external references.

Original Description

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 server that emits one small chunk every Timeout - 1 ms with Fin = false and never sends a final frame keeps the loop alive indefinitely while the accumulation buffer grows linearly without bound, eventually exhausting the BEAM process heap and causing an out-of-memory condition.

This issue affects hackney: from 2.0.0 before 4.0.1.

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-30T17:00:40Z",
    "nvd_published_at":  "2026-05-25T15:16:22Z",
    "severity":  "HIGH"
}
References

Affected packages

Hex / hackney

Package

Name
hackney
Purl
pkg:hex/hackney

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
4.0.1

Affected versions

2.*
2.0.0
2.0.1
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
4.*
4.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-76v6-f83q-pxvh/GHSA-76v6-f83q-pxvh.json"