{"id":"CVE-2026-47067","title":"Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes","summary":"Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes","severity":"high","cwe":["CWE-770"],"vendor":"hackney","product":"hackney","ecosystem":"erlang","affected":["hackney >= 2.0.0, < 4.0.1"],"patched":["hackney 4.0.1"],"published":"2026-06-26","updated":"2026-06-26","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-9653-rcfr-5c62","references":[{"url":"https://github.com/benoitc/hackney/security/advisories/GHSA-9653-rcfr-5c62"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47067"},{"url":"https://github.com/benoitc/hackney/commit/31f6f0e27e096ad88743dfded4f030a3ee74972e"},{"url":"https://cna.erlef.org/cves/CVE-2026-47067.html"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-47067"},{"url":"https://github.com/advisories/GHSA-9653-rcfr-5c62"}],"tags":["ghsa","erlang"],"epss":0.00753,"epssPercentile":0.53127,"ingestedAt":"2026-06-29T13:24:35.104Z","slug":"CVE-2026-47067","body":"## Overview\n\n### Summary\n\n[CVE-2026-47067](https://nvd.nist.gov/vuln/detail/CVE-2026-47067) is an atom table exhaustion vulnerability (CWE-770) in hackney's URL parser (`src/hackney_url.erl`). `hackney_url:parse_url/1` converts every URL scheme it encounters into a BEAM atom via `binary_to_atom/2`. Because BEAM atoms are never garbage-collected and the atom table has a hard limit of 1,048,576 entries, an attacker who can feed URLs with attacker-chosen scheme prefixes — directly as request targets, as webhook/callback URLs, or via `Location` headers in redirect chains — can exhaust the atom table and crash the entire BEAM VM with `system_limit`.\n\n### Details\n\n**1. Scheme extraction and conversion**\n\nIn `src/hackney_url.erl`, `parse_url/1` extracts the scheme binary (the part before `://`), validates it with `is_valid_scheme/1` (RFC 3986 alphabet: alpha-led, `<=19` bytes, alphanumeric/`+`/`-`/`.` body), lowercases it, then calls:\n\n```erlang\nbinary_to_atom(SchemeLower, utf8)\n```\n\nThe resulting atom is stored on the `#hackney_url{}` record and returned to the caller.\n\n**2. Permanent atom accumulation**\n\nThe validation constrains the alphabet but not uniqueness. The allowed scheme space is enormous (≈52·65¹⁸ values), far exceeding the default atom limit of 1,048,576. Each distinct scheme mints a new permanent atom. Even when hackney subsequently rejects an unsupported scheme with `{error, {unsupported_scheme, _}}`, the atom has already been interned and is never reclaimed.\n\n**3. Crash vector**\n\nThe most dangerous path is redirect following: when hackney follows a `Location` header, the redirect target URL is re-parsed by the same function. An attacker-controlled server can serve a sequence of redirects — or a batch of URLs from an upstream feed — each with a fresh unique scheme, driving the atom count monotonically upward. At the limit the BEAM emits `system_limit` and the node terminates; recovery requires a full restart.\n\n### PoC\n\n1. Call `hackney_url:parse_url/1` (or `:hackney.request/5`) repeatedly with URLs whose scheme prefixes are unique on each call: `aaaa://x`, `aaab://x`, `aaac://x`, …\n2. After enough iterations, observe `erlang:system_info(:atom_count)` climbing by one per unique scheme.\n3. At 1,048,576 atoms the VM crashes with `system_limit`.\n\nAlternatively, point hackney at a server that replies with a feed of ~1M URLs with distinct schemes (or uses redirect chains with rotating schemes); the atom table is exhausted and the node crashes without the client being able to intervene.\n\n### Impact\n\nUnauthenticated remote denial of service via permanent resource exhaustion leading to VM termination. Any application using hackney 2.0.0 through 4.0.0 that processes attacker-influenced URLs — direct request targets, webhook URLs, or `Location` headers in followed redirects — is affected. No authentication or special configuration is required. CVSS v4.0 score: **8.7 (HIGH)**.\n\n## References\n\n* Introduction commit: https://github.com/benoitc/hackney/commit/d9713695c0d99855d12c73fd8a0b4be0543950c4\n* Patch commit: https://github.com/benoitc/hackney/commit/31f6f0e27e096ad88743dfded4f030a3ee74972e\n\n## Affected packages\n\n- `hackney >= 2.0.0, < 4.0.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `hackney 4.0.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}