<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:15:02.472533+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322107</id>
    <title>EUVD-2026-322107</title>
    <updated>2026-10-06T07:15:02.534011+00:00</updated>
    <content>EUVD-2026-322107</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322107"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47073</id>
    <title>fkie_cve-2026-47073</title>
    <updated>2026-10-06T07:15:02.534056+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three code paths. First, read_handshake_response/3 accumulates received bytes into a growing buffer with no size cap; the per-receive timeout resets on every chunk, so a server that streams bytes without ever sending \r\n\r\n causes the buffer to grow until memory is exhausted. Second, parse_payload/9 and parse_active_payload/8 do not validate the declared frame payload length against any limit; because RFC 6455 allows payload lengths up to 2^63-1 bytes, a server that announces a very large frame and dribbles bytes causes the accumulation buffer to grow until OOM. Third, the frag_buffer field in #ws_data{} accumulates continuation frames indefinitely; a server that sends an endless stream of non-final (nofin) fragmented frames without ever sending a final (fin) frame grows frag_buffer without bound.</p>
<p>In all three cases the attacker only needs to control the WebSocket server the hackney client connects to, with no authentication or special client configuration required.</p>
<p>This issue affects hackney: from 2.0.0 before 4.0.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q8jg-fgj4-fphf</id>
    <title>GHSA-q8jg-fgj4-fphf — Hackney has unbounded buffer accumulation in WebSocket</title>
    <updated>2026-10-06T07:15:02.534101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: hackney</p>
<p>### Summary</p>
<p>The WebSocket client in `src/hackney_ws.erl` imposes no upper bound on memory consumption across three distinct code paths. In each case, an attacker-controlled WebSocket server can exhaust the connecting process's memory without any authentication or special client configuration.</p>
<p>### Details</p>
<p>**1. Handshake response buffer (`read_handshake_response/3`)**</p>
<p>The function accumulates received bytes into a growing buffer waiting for `\r\n\r\n`. The per-receive timeout resets on every chunk, so a server that trickles bytes indefinitely without completing the HTTP upgrade response grows the buffer until OOM. No total-size cap exists.</p>
<p>**2. Frame payload accumulation (`parse_payload/9`, `parse_active_payload/8`)**</p>
<p>`parse_payload/9` (lines 816–817 and 825–826) appends each received chunk into a `Buffer` binary via `&lt;&lt;Buffer/binary, MoreData/binary&gt;&gt;` whenever the frame parser returns `{more, ...}`. `parse_active_payload/8` does the same in active mode by appending each incoming `tcp`/`ssl` message to `#ws_data.buffer`. RFC 6455 permits payload lengths up to 2⁶³-1 bytes, and neither path validates the declared `Len` against any limit. The `recv_timeout` applies per chunk, not to the whole frame, so a slow trickle never triggers it.</p>
<p>**3. Fragmentation buffer (`frag_buffer`)**</p>
<p>The `frag_buffer` field of `#ws_data{}` accumulates continuation frames. A server that sends an unbounded stream of non-final (`nofin`) fragments without ever sending a final (`fin`) frame grows…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q8jg-fgj4-fphf"/>
  </entry>
</feed>
