CVE-2026-47072
Last modified
CVE-2026-47072 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/Response Splitting. The WebSocket upgrade code in src/hackney_ws.erl copies the host, path, headers (ExtraHeaders), and protocols options from the caller-supplied opts map into the internal #ws_data{} record in init/1 and then splices them verbatim into the raw HTTP/1.1 upgrade request by binary concatenation in do_handshake/1. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/Response Splitting. The WebSocket upgrade code in src/hackney_ws.erl copies the host, path, headers (ExtraHeaders), and protocols options from the caller-supplied opts map into the internal #ws_data{} record in init/1 and then splices them verbatim into the raw HTTP/1.1 upgrade request by binary concatenation in do_handshake/1. No CRLF or NUL stripping is performed at any of these four injection sites. An attacker who controls any of these options — for example by forwarding URL components or header values from untrusted input into hackney_ws:start_link/1 — can inject arbitrary HTTP headers into the outbound WebSocket upgrade request, leading to header injection, credential spoofing toward the upstream server, log and cache poisoning, or request smuggling via intermediary proxies. This issue affects hackney: from 2.0.0 before 4.0.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Benoitc | Hackney | >= 2.0.0, < 4.0.1 |
References
- https://cna.erlef.org/cves/CVE-2026-47072.htmlPatch, Third Party Advisory
- https://github.com/benoitc/hackney/security/advisories/GHSA-f9vr-g2g2-x9fgExploit, Patch, Vendor Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-47072Patch, Third Party Advisory
- https://github.com/benoitc/hackney/security/advisories/GHSA-f9vr-g2g2-x9fgExploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-47072?
How severe is CVE-2026-47072?
How do I fix CVE-2026-47072?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47067Allocation of Resources Without Limits or Throttling vulnera…7.5
- CVE-2026-47068Authorization Bypass Through User-Controlled Key vulnerabili…2.3
- CVE-2026-47069Improper Neutralization of CRLF Sequences ('CRLF Injection')…5.3
- CVE-2026-4707Incorrect boundary conditions in the Graphics: Canvas2D comp…7.5
- CVE-2026-47070Sensitive Data Exposure vulnerability in benoitc hackney all…6.1
- CVE-2026-47071Uncontrolled Resource Consumption vulnerability in benoitc h…7.5
- CVE-2026-47073Allocation of Resources Without Limits or Throttling vulnera…7.5
- CVE-2026-47074Improper Certificate Validation vulnerability in ex-aws ex_a…8.7
- CVE-2026-47075Improper Neutralization of CRLF Sequences vulnerability in b…7.5
- CVE-2026-47076Interpretation Conflict vulnerability in benoitc hackney all…6.5
- CVE-2026-47077Allocation of Resources Without Limits or Throttling vulnera…7.5
- CVE-2026-47078Relative Path Traversal vulnerability in Erlang OTP (stdlib …4.8
Are you affected by CVE-2026-47072?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
