GHSA-q8jg-fgj4-fphf

Suggest an improvement
Source
https://github.com/advisories/GHSA-q8jg-fgj4-fphf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q8jg-fgj4-fphf/GHSA-q8jg-fgj4-fphf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q8jg-fgj4-fphf
Aliases
Published
2026-06-26T22:00:16Z
Modified
2026-06-26T22:15:08Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Hackney has unbounded buffer accumulation in WebSocket
Details

Summary

The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption across three distinct code paths. In each case, an attacker-controlled WebSocket server can exhaust the connecting process's memory without any authentication or special client configuration.

Details

1. Handshake response buffer (read_handshake_response/3)

The function accumulates received bytes into a growing buffer waiting for \r\n\r\n. The per-receive timeout resets on every chunk, so a server that trickles bytes indefinitely without completing the HTTP upgrade response grows the buffer until OOM. No total-size cap exists.

2. Frame payload accumulation (parse_payload/9, parse_active_payload/8)

parse_payload/9 (lines 816–817 and 825–826) appends each received chunk into a Buffer binary via <<Buffer/binary, MoreData/binary>> whenever the frame parser returns {more, ...}. parse_active_payload/8 does the same in active mode by appending each incoming tcp/ssl message to #ws_data.buffer. RFC 6455 permits payload lengths up to 2⁶³-1 bytes, and neither path validates the declared Len against any limit. The recv_timeout applies per chunk, not to the whole frame, so a slow trickle never triggers it.

3. Fragmentation buffer (frag_buffer)

The frag_buffer field of #ws_data{} accumulates continuation frames. A server that sends an unbounded stream of non-final (nofin) fragments without ever sending a final (fin) frame grows frag_buffer without bound.

PoC

  1. Stand up a WebSocket server and connect to it with hackney's WebSocket client.
  2. Trigger any of the three paths: (a) never send \r\n\r\n during the handshake; (b) announce a very large frame payload and dribble bytes slowly; (c) send an endless stream of nofin continuation frames.
  3. Observe the hackney process's memory growing until the BEAM OOM-kills it or the node crashes.

Impact

Denial of service via unbounded memory consumption. Affects hackney 2.0.0 through 4.0.0 for any application using the WebSocket client against an attacker-controlled server. No authentication or special configuration is required on the client side. CVSS v4.0: 8.7 (HIGH).

Resources

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-26T22:00:16Z",
    "nvd_published_at":  "2026-05-25T15:16:22Z",
    "severity":  "HIGH"
}
References

Affected packages

Hex / hackney

Package

Name
hackney
Purl
pkg:hex/hackney

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
4.0.1

Affected versions

2.*
2.0.0
2.0.1
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
4.*
4.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q8jg-fgj4-fphf/GHSA-q8jg-fgj4-fphf.json"