Signal

Multiple vulnerabilities discovered in Hackney HTTP client library

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-26 21:58 UTCUpdated 2026-06-26 22:01 UTC
github
cvesecurity_advisoryvulnerabilityexploit_potential
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (1 domains)domains are deduped. counts indicate coverage, not truth.
1 top source shown
limited source diversity in top sources
Overview

Four security vulnerabilities have been identified in the Hackney HTTP client library, including two medium-severity CRLF injection flaws affecting WebSocket upgrade requests and query parameters, and two high-severity issues involving unbounded buffer accumulation in...

Entities
Hackney
Score total
0.89
Momentum 24h
4
Posts
4
Origins
1
Source types
1
Duplicate ratio
0%
Why now
  • The advisories were published recently, indicating fresh security risks.
  • High-severity vulnerabilities require immediate attention to prevent exploitation.
  • Hackney is widely used, so timely updates are essential to protect dependent systems.
Why it matters
  • These vulnerabilities could allow attackers to perform header injection and resource exhaustion attacks.
  • Unpatched flaws may lead to system instability or denial of service in applications using Hackney.
  • Prompt awareness and patching are critical to maintaining secure HTTP client operations.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Hackney has CRLF injection vulnerabilities in WebSocket upgrade requests and query parameters
  • Hackney suffers from high-severity unbounded buffer accumulation and atom-table exhaustion vulnerabilities
How sources frame it
  • Github_advisories: neutral
All evidence
All evidence
GitHub Security Advisories
github.com · github.com · 2026-06-26 21:59 UTC
Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes
github_advisories · github.com · 2026-06-26 22:01 UTC
Hackney has unbounded buffer accumulation in WebSocket
github_advisories · github.com · 2026-06-26 22:00 UTC
Hackney has CR/LF injection in query parameter
github_advisories · github.com · 2026-06-26 21:58 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 1Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • github_advisories (3)
  • github.com (1)
Top origin domains (this list)
  • github.com (4)