Hackney fails to properly release HTTP connections to the pool
Low severity
GitHub Reviewed
Published
May 28, 2025
to the GitHub Advisory Database
•
Updated May 28, 2025
Description
Published by the National Vulnerability Database
May 28, 2025
Published to the GitHub Advisory Database
May 28, 2025
Reviewed
May 28, 2025
Last updated
May 28, 2025
Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, causing denial of service in applications using the library.
Fix for this issue has been included in 1.24.0 release.
References