highVulnerability

CVE-2026-47066

### Summary [CVE-2026-47066](https://nvd.nist.gov/vuln/detail/CVE-2026-47066) is an infinite loop (CWE-835) in hackney's Alt-Svc response header parser (`src/hackney_altsvc.erl`). When an HTTP server returns an `Alt-Svc` header whose value begins with a non-token byte (e.g. `!`, `@`, `=`, `;`), the parser enters a tight tail-recursive loop that pins an Erlang scheduler at 100% CPU and permanently hangs the calling connection process. Because the parser is invoked synchronously on every HTTP response, any attacker-controlled origin can trigger the hang with a single-byte header value. ### Details **1. Parser dispatch** `parse_and_cache/3` is called inside the hackney connection process on each HTTP response. It collects all `Alt-Svc` header values via `collect_altsvc_headers/1`, concatenates them, and passes the result to `parse/1`, which calls `parse_entries(Header, [])`. **2. Failed token consumption** `parse_entries/2` → `parse_entry/1` → `parse_protocol/1` → `parse_token(Data, <<>>)`. The function `parse_token/2` pattern-matches leading bytes: alphanumeric, `-`, `_`, whitespace, and comma all have explicit clauses. Any other byte (e.g. `!`) falls through to the catch-all: ```erlang parse_token(Rest, <<>>) -> {undefined, Rest}. ``` This returns the *input unchanged* — no byte is consumed. **3. No-progress loop** `parse_entry` propagates `{undefined, Rest}` back to `parse_entries/2`, which calls `skip_comma(Rest)`. Because the first byte is not `,`, `skip_comma` also returns `Rest` unchanged. `parse_entries` then recurses with the identical buffer: ```erlang parse_entries(Data, Acc) % Data identical to previous iteration ``` Erlang tail recursion never preempts on a pure CPU loop, so the scheduler is pinned and the process never yields or returns. **4. Root cause** `parse_entries/2` has no guard that detects zero-byte progress after a failed `parse_entry` call and no fallback to advance past the offending byte. ### PoC 1. Start an HTTP server that

Properties

ghsa_id
GHSA-6cp8-v795-jr2j
summary
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
severity
high
epss_score
0.00753
cve_id
CVE-2026-47066
is_ghsa_only
false
ghsa_published
2026-06-26T21:53:07Z
source_url
https://github.com/advisories/GHSA-6cp8-v795-jr2j
epss_percentile
0.5164
ghsa_updated
2026-06-26T21:54:55Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]erlang/hackney

AFFECTS (1)

[Software]erlang/hackney

HAS_WEAKNESS (1)

[Weakness]Loop with Unreachable Exit Condition ('Infinite Loop')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-47066 — Ninja Signal Threat Intelligence | Ninja Signal