HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-47071 — Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Floodi...

·Source: NIST NVD

Updated:

Executive Summary

Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to the SOCKS5 negotiation phase, but then upgrades the connection to TLS using the two-argument form ssl:connect/2, which defaults to an infinite timeout. The Timeout value is in scope at the call site but is not forwarded.

Analysis

Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to the SOCKS5 negotiation phase, but then upgrades the connection to TLS using the two-argument form ssl:connect/2, which defaults to an infinite timeout. The Timeout value is in scope at the call site but is not forwarded. A hostile SOCKS5 proxy that completes the SOCKS5 handshake normally and then goes silent (or sends a partial TLS ServerHello and stalls) will cause the connecting process to block indefinitely, regardless of the connect_timeout or recv_timeout options supplied by the caller. This issue affects hackney: from 0.10.0 before 4.0.1. CVSS Score: 7.5. Published: 2026-05-25T15:16:22.143.

Indicators of Compromise (1)

CVE (1)
CVE-2026-47071
Source Attribution

Originally published by NIST NVD on May 25, 2026. Verified by: NIST.

Related Threats