CVE-2026-47076 Details
Description
Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{} record. OTP's uri_string:parse/1 and inet:parse_address/1 do not decode percent-escapes in the host, so a URL such as http://%31%32%37%2E%30%2E%30%2E%31/ is seen by a caller's allowlist validator with host %31%32%37%2E%30%2E%30%2E%31 (not an IP address), which passes the allowlist check. hackney's normalizer then decodes the host to 127.0.0.1 and opens a TCP connection to loopback. Because hackney:request/5 always calls hackney_url:normalize/2 with no opt-out, every request that takes a binary or list URL is affected. The same technique reaches cloud instance metadata services (169.254.169.254), RFC1918 networks, and any admin interface listening on localhost. This issue affects hackney: from 0.13.0 before 4.0.1.
A vulnerability in the Benoitc Hackney HTTP client library, specifically in versions 0.13.0 prior to 4.0.1, allows for Server-Side Request Forgery (SSRF) by exploiting an interpretation conflict in how URLs are normalized. The issue arises because the normalization process decodes percent-encoded host components after the URL has been validated against an allowlist. This allows an attacker to craft a URL that bypasses the allowlist and redirects requests to internal services or metadata endpoints.
Users can upgrade to Hackney version 4.0.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/benoitc/hackney/security/advisories/GHSA-pj7v-xfvx-wmjq | CISA-ADP | ExploitPatchVendor Advisory |
| https://cna.erlef.org/cves/CVE-2026-47076.html | EEF | PatchThird Party Advisory |
| https://github.com/benoitc/hackney/commit/452620a92ec1da2e6b4862a049a2a4f04b42068f | EEF | Patch |
| https://github.com/benoitc/hackney/security/advisories/GHSA-pj7v-xfvx-wmjq | EEF | ExploitPatchVendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-47076 | EEF | PatchThird Party Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| benoitc hackney | >= 0.13.0, < 4.0.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 26, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | EEF |