NVD HIGH: CVE-2026-47077 — Allocation of Resources Without Limits or Throttling vulnerability in benoitc ha...
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 serve
CVE-2026-47077