CVE-2026-47066
### Summary [CVE-2026-47066](https://nvd.nist.gov/vuln/detail/CVE-2026-47066) is an infinite loop (CWE-835) in hackney's Alt-Svc response header parser (`src/hackney_altsvc.erl`). When an HTTP server returns an `Alt-Svc` header whose value begins with a non-token byte (e.g. `!`, `@`, `=`, `;`), the parser enters a tight tail-recursive loop that pins an Erlang scheduler at 100% CPU and permanently hangs the calling connection process. Because the parser is invoked synchronously on every HTTP response, any attacker-controlled origin can trigger the hang with a single-byte header value. ### Details **1. Parser dispatch** `parse_and_cache/3` is called inside the hackney connection process on each HTTP response. It collects all `Alt-Svc` header values via `collect_altsvc_headers/1`, concatenates them, and passes the result to `parse/1`, which calls `parse_entries(Header, [])`. **2. Failed token consumption** `parse_entries/2` → `parse_entry/1` → `parse_protocol/1` → `parse_token(Data, <<>>)`. The function `parse_token/2` pattern-matches leading bytes: alphanumeric, `-`, `_`, whitespace, and comma all have explicit clauses. Any other byte (e.g. `!`) falls through to the catch-all: ```erlang parse_token(Rest, <<>>) -> {undefined, Rest}. ``` This returns the *input unchanged* — no byte is consumed. **3. No-progress loop** `parse_entry` propagates `{undefined, Rest}` back to `parse_entries/2`, which calls `skip_comma(Rest)`. Because the first byte is not `,`, `skip_comma` also returns `Rest` unchanged. `parse_entries` then recurses with the identical buffer: ```erlang parse_entries(Data, Acc) % Data identical to previous iteration ``` Erlang tail recursion never preempts on a pure CPU loop, so the scheduler is pinned and the process never yields or returns. **4. Root cause** `parse_entries/2` has no guard that detects zero-byte progress after a failed `parse_entry` call and no fallback to advance past the offending byte. ### PoC 1. Start an HTTP server that
Properties
- ghsa_id
- GHSA-6cp8-v795-jr2j
- summary
- Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
- severity
- high
- epss_score
- 0.00753
- cve_id
- CVE-2026-47066
- is_ghsa_only
- false
- ghsa_published
- 2026-06-26T21:53:07Z
- source_url
- https://github.com/advisories/GHSA-6cp8-v795-jr2j
- epss_percentile
- 0.5164
- ghsa_updated
- 2026-06-26T21:54:55Z
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph