<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:54:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322107</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322107</link>
      <description>EUVD-2026-322107</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322107</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47073</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47073</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three code paths. First, read_handshake_response/3 accumulates received bytes into a growing buffer with no size cap; the per-receive timeout resets on every chunk, so a server that streams bytes without ever sending \r\n\r\n causes the buffer to grow until memory is exhausted. Second, parse_payload/9 and parse_active_payload/8 do not validate the declared frame payload length against any limit; because RFC 6455 allows payload lengths up to 2^63-1 bytes, a server that announces a very large frame and dribbles bytes causes the accumulation buffer to grow until OOM. Third, the frag_buffer field in #ws_data{} accumulates continuation frames indefinitely; a server that sends an endless stream of non-final (nofin) fragmented frames without ever sending a final (fin) frame grows frag_buffer without bound.&lt;/p&gt;
&lt;p&gt;In all three cases the attacker only needs to control the WebSocket server the hackney client connects to, with no authentication or special client configuration required.&lt;/p&gt;
&lt;p&gt;This issue affects hackney: from 2.0.0 before 4.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three code paths. First, read_handshake_response/3 accumulates received bytes into a growing buffer with no size cap; the per-receive timeout resets on every chunk, so a server that streams bytes without ever sending \r\n\r\n causes the buffer to grow until memory is exhausted. Second, parse_payload/9 and parse_active_payload/8 do not validate the declared frame payload length against any limit; because RFC 6455 allows payload lengths up to 2^63-1 bytes, a server that announces a very large frame and dribbles bytes causes the accumulation buffer to grow until OOM. Third, the frag_buffer field in #ws_data{} accumulates continuation frames indefinitely; a server that sends an endless stream of non-final (nofin) fragmented frames without ever sending a final (fin) frame grows frag_buffer without bound.&lt;/p&gt;
&lt;p&gt;In all three cases the attacker only needs to control the WebSocket server the hackney client connects to, with no authentication or special client configuration required.&lt;/p&gt;
&lt;p&gt;This issue affects hackney: from 2.0.0 before 4.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47073</guid>
    </item>
    <item>
      <title>GHSA-q8jg-fgj4-fphf — Hackney has unbounded buffer accumulation in WebSocket</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q8jg-fgj4-fphf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: hackney&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The WebSocket client in `src/hackney_ws.erl` imposes no upper bound on memory consumption across three distinct code paths. In each case, an attacker-controlled WebSocket server can exhaust the connecting process&amp;#39;s memory without any authentication or special client configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**1. Handshake response buffer (`read_handshake_response/3`)**&lt;/p&gt;
&lt;p&gt;The function accumulates received bytes into a growing buffer waiting for `\r\n\r\n`. The per-receive timeout resets on every chunk, so a server that trickles bytes indefinitely without completing the HTTP upgrade response grows the buffer until OOM. No total-size cap exists.&lt;/p&gt;
&lt;p&gt;**2. Frame payload accumulation (`parse_payload/9`, `parse_active_payload/8`)**&lt;/p&gt;
&lt;p&gt;`parse_payload/9` (lines 816–817 and 825–826) appends each received chunk into a `Buffer` binary via `&amp;lt;&amp;lt;Buffer/binary, MoreData/binary&amp;gt;&amp;gt;` whenever the frame parser returns `{more, ...}`. `parse_active_payload/8` does the same in active mode by appending each incoming `tcp`/`ssl` message to `#ws_data.buffer`. RFC 6455 permits payload lengths up to 2⁶³-1 bytes, and neither path validates the declared `Len` against any limit. The `recv_timeout` applies per chunk, not to the whole frame, so a slow trickle never triggers it.&lt;/p&gt;
&lt;p&gt;**3. Fragmentation buffer (`frag_buffer`)**&lt;/p&gt;
&lt;p&gt;The `frag_buffer` field of `#ws_data{}` accumulates continuation frames. A server that sends an unbounded stream of non-final (`nofin`) fragments without ever sending a final (`fin`) frame grows…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: hackney&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The WebSocket client in `src/hackney_ws.erl` imposes no upper bound on memory consumption across three distinct code paths. In each case, an attacker-controlled WebSocket server can exhaust the connecting process&amp;#39;s memory without any authentication or special client configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**1. Handshake response buffer (`read_handshake_response/3`)**&lt;/p&gt;
&lt;p&gt;The function accumulates received bytes into a growing buffer waiting for `\r\n\r\n`. The per-receive timeout resets on every chunk, so a server that trickles bytes indefinitely without completing the HTTP upgrade response grows the buffer until OOM. No total-size cap exists.&lt;/p&gt;
&lt;p&gt;**2. Frame payload accumulation (`parse_payload/9`, `parse_active_payload/8`)**&lt;/p&gt;
&lt;p&gt;`parse_payload/9` (lines 816–817 and 825–826) appends each received chunk into a `Buffer` binary via `&amp;lt;&amp;lt;Buffer/binary, MoreData/binary&amp;gt;&amp;gt;` whenever the frame parser returns `{more, ...}`. `parse_active_payload/8` does the same in active mode by appending each incoming `tcp`/`ssl` message to `#ws_data.buffer`. RFC 6455 permits payload lengths up to 2⁶³-1 bytes, and neither path validates the declared `Len` against any limit. The `recv_timeout` applies per chunk, not to the whole frame, so a slow trickle never triggers it.&lt;/p&gt;
&lt;p&gt;**3. Fragmentation buffer (`frag_buffer`)**&lt;/p&gt;
&lt;p&gt;The `frag_buffer` field of `#ws_data{}` accumulates continuation frames. A server that sends an unbounded stream of non-final (`nofin`) fragments without ever sending a final (`fin`) frame grows…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q8jg-fgj4-fphf</guid>
    </item>
  </channel>
</rss>
