Sensitive Data Exposure in Hackney HTTP Client from Benoit C
CVE-2026-47070

6MEDIUM

Key Information:

Vendor

Benoitc

Status
Vendor
CVE Published:
25 May 2026

What is CVE-2026-47070?

A vulnerability in the Hackney HTTP client allows for sensitive data exposure due to unvalidated forwarding of original request headers during HTTP/3 redirects. When a client sends a request with follow_redirect enabled and includes sensitive information in the Authorization or Cookie headers, a redirect response can lead to those credentials being sent unguarded to another host. This flaw arises from the lack of proper cross-origin checks in the HTTP/3 redirect handler, which fails to correctly process and secure the sensitive data, thereby heightening risks of credential leakage.

Affected Version(s)

hackney 3.1.1 < 4.0.1

hackney e61b7d04b7826847e1efe614106ef4d580c78eab

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Benoit Chesneau
Jonatan Männchen
.