Hackney fails to properly release HTTP connections to the pool
Low severity
GitHub Reviewed
Published
May 28, 2025
to the GitHub Advisory Database
•
Updated Jan 29, 2026
Description
Published by the National Vulnerability Database
May 28, 2025
Published to the GitHub Advisory Database
May 28, 2025
Reviewed
May 28, 2025
Last updated
Jan 29, 2026
Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, causing denial of service in applications using the library.
Fix for this issue has been included in 1.24.0 release.
References