GHSA-f9vr-g2g2-x9fg

Suggest an improvement
Source
https://github.com/advisories/GHSA-f9vr-g2g2-x9fg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-f9vr-g2g2-x9fg/GHSA-f9vr-g2g2-x9fg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f9vr-g2g2-x9fg
Aliases
Published
2026-06-26T21:59:44Z
Modified
2026-06-26T22:15:08Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N CVSS Calculator
Summary
Hackney has CRLF / header injection in WebSocket upgrade request
Details

Summary

CRLF injection in hackney's WebSocket upgrade request builder (src/hackney_ws.erl). init/1 copies the host, path, headers, and protocols options from the caller-supplied opts map verbatim into #ws_data{}, and do_handshake/1 splices them directly into the raw HTTP/1.1 upgrade request by binary concatenation with no \r\n or \0 stripping. A caller that passes any of these fields from untrusted input can inject arbitrary header lines into the outbound upgrade request.

Details

do_handshake/1 builds the upgrade request at several concatenation sites:

  • Host header (lines 583–590): the host binary is written straight into Host: <host>:<port>\r\n.
  • Sec-WebSocket-Protocol (lines 601–602): protocol tokens are joined with , and appended as a header line.
  • Extra headers (line 606): caller-supplied {Name, Value} tuples are concatenated as Name: Value\r\n with no sanitization of either component.
  • Request path (line 611): the path is interpolated into the GET <path> HTTP/1.1\r\n request line.

None of these sites reject \r, \n, or \0. A header value like <<"benign\r\nAuthorization: Bearer token">> produces two distinct header lines on the wire. A path with an embedded \r\n rewrites the request line itself.

PoC

  1. Call :hackney_ws.start_link/1 with headers: [{"X-User", "v\r\nAuthorization: Bearer attacker"}].
  2. Connect to a raw TCP listener and capture the bytes hackney writes.
  3. The request contains a standalone Authorization: Bearer attacker line that the upstream WebSocket server parses as a legitimate header.

Impact

Header injection / request smuggling in outbound WebSocket upgrades. Affects hackney 2.0.0 through 4.0.0 wherever host, path, headers, or protocols options are populated from network or user input. Consequences include forging authentication headers toward the upstream server, log and cache poisoning, and request smuggling through intermediary proxies. CVSS v4.0: 6.9 (MEDIUM).

Resources

Database specific
{
    "cwe_ids":  [
        "CWE-93"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-26T21:59:44Z",
    "nvd_published_at":  "2026-05-25T15:16:22Z",
    "severity":  "MODERATE"
}
References

Affected packages

Hex / hackney

Package

Name
hackney
Purl
pkg:hex/hackney

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
4.0.1

Affected versions

2.*
2.0.0
2.0.1
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
4.*
4.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-f9vr-g2g2-x9fg/GHSA-f9vr-g2g2-x9fg.json"