{"id":"CVE-2026-47069","title":"Hackney has CRLF / header injection via unvalidated `domain` and `path` options","summary":"Hackney has CRLF / header injection via unvalidated `domain` and `path` options","severity":"low","cwe":["CWE-93"],"vendor":"hackney","product":"hackney","ecosystem":"erlang","affected":["hackney >= 0.9.0, < 4.0.1"],"patched":["hackney 4.0.1"],"published":"2026-06-26","updated":"2026-06-26","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-mp55-p8c9-rfw2","references":[{"url":"https://github.com/benoitc/hackney/security/advisories/GHSA-mp55-p8c9-rfw2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47069"},{"url":"https://github.com/benoitc/hackney/commit/8e02b99c28aea1b3fa2ddc0e66f51fe5bb0ac540"},{"url":"https://cna.erlef.org/cves/CVE-2026-47069.html"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-47069"},{"url":"https://github.com/advisories/GHSA-mp55-p8c9-rfw2"}],"tags":["ghsa","erlang"],"epss":0.00425,"epssPercentile":0.36327,"ingestedAt":"2026-06-29T13:24:35.111Z","slug":"CVE-2026-47069","body":"## Overview\n\n### Summary\n\nCRLF injection in `hackney_cookie:setcookie/3` (`src/hackney_cookie.erl`). The function validates `Name` and `Value` against CR/LF and control characters but concatenates the `domain` and `path` options verbatim into the output binary. If either option carries attacker-controlled data, a `Host` header forwarded as the cookie domain, a request URI forwarded as the cookie path, a `\\r\\n` in the value splits the `Set-Cookie` header and lets the attacker inject additional headers into the HTTP response.\n\n### Details\n\n**1. Asymmetric validation**\n\nLines 27–34 of `hackney_cookie.erl` run `binary:match` on `Name` and `Value`, rejecting `=`, `,`, `;`, whitespace, `\\r`, `\\n`, `\\013`, and `\\014`. The `Domain` and `Path` options (lines 47 and 51) skip this check entirely and land straight in the result iolist:\n\n```erlang\n[<<\"; Domain=\">>, Domain]\n[<<\"; Path=\">>,   Path]\n```\n\n`iolist_to_binary(...)` on line 63 flattens everything and returns it to the caller.\n\n**2. Injection**\n\nA `Path` of `<<\"/x\\r\\nSet-Cookie: admin=1; Path=/\">>` produces a binary with a literal `\\r\\n`. Written into a `Set-Cookie` response header, the receiving HTTP parser splits it into two headers — one legitimate, one attacker-controlled.\n\n**3. Realistic trigger**\n\nCommon patterns: keying the cookie domain off `Host`, deriving the path from the request URI, or copying a `Location` path into a cookie. Any of these lets a remote attacker control the injected content.\n\n### PoC\n\n1. Call `hackney_cookie:setcookie(<<\"sid\">>, <<\"abc\">>, [{path, <<\"/x\\r\\nSet-Cookie: admin=1; Path=/\">>}])`.\n2. The returned binary contains a literal `\\r\\n` followed by a second `Set-Cookie:` line.\n3. Write the result into a `Set-Cookie` response header — the client parses two headers, including `admin=1`.\n\n### Impact\n\nCookie injection / HTTP response splitting at the `hackney_cookie` API boundary. Affects hackney 0.9.0 through 4.0.0 wherever `domain` or `path` options are populated from request data. Exploitation can overwrite session/auth cookies, fix cookies, or strip `Secure`/`HttpOnly` flags. CVSS v4.0: **2.1 (LOW)** — requires attacker-controlled input to reach the `domain` or `path` option.\n\n## Resources\n\n* Introduction commit: https://github.com/benoitc/hackney/commit/602d5c7f2ea4acbc83ed75230655d935a0750ebc\n* Patch commit: https://github.com/benoitc/hackney/commit/8e02b99c28aea1b3fa2ddc0e66f51fe5bb0ac540\n\n## Affected packages\n\n- `hackney >= 0.9.0, < 4.0.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `hackney 4.0.1`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}