Download Latest Version 4.7.4 source code.zip (477.0 kB)
Email in envelope

Get an email when there's a new version of hackney

Home / 4.7.3
Name Modified Size InfoDownloads / Week
Parent folder
4.7.3 source code.tar.gz 2026-08-11 374.7 kB
4.7.3 source code.zip 2026-08-11 458.1 kB
README.md 2026-08-11 2.8 kB
Totals: 3 Items   835.6 kB 0

hackney 4.7.3 is a bugfix and hardening release for the Erlang HTTP client. It clears a few ways a pooled connection could stall or leak, hardens CRLF handling on the proxy and streaming request paths, restores curl-style Content-Length: 0 on empty POST/PUT/PATCH bodies (so servers such as AWS that require the header are happy again), and refreshes every dependency to its latest release.

Upgrading from 4.7.2 needs no code changes.

Fixed

  • Reusing a pooled HTTP/2 or HTTP/3 connection no longer crashes the caller of hackney:connect/4 when the pooled connection terminates during the checkout liveness probe. The get_state probe is guarded so a terminating connection falls through to a fresh one (#914).
  • hackney_url:normalize/2 now rejects a host that reaches an IP literal only after IDNA folds the Unicode full-stop variants (U+3002/U+FF0E/U+FF61) to ASCII dots (for example 127。0。0。1 becoming 127.0.0.1), closing a bypass of the percent-encoded-IP check.
  • The CONNECT proxy handshake rejects CR/LF/NUL in the target host instead of concatenating it into the request line and Host header.
  • The pooled HTTPS upgrade bounds the TLS handshake with connect_timeout (ssl:connect/3), so a server that stalls the handshake no longer pins the connection process and its pool slot (#916).
  • The streaming request path sanitizes header values (CR/LF) like the buffered path, and the request method is validated (CR/LF/NUL) at every entry point, not just the request target.
  • A response body cut short by the peer closing mid-transfer no longer leaks the connection process. read_full_body/2 hands back socket = undefined, so the connection went straight to closed and never reached the reuse check added for [#902]. An unpooled connection arms no grace timer there and, when started under hackney_conn_sup, has the supervisor as its owner, so the owner-DOWN clause never fired either: the process parked forever holding every refc binary it had read. Callers could not clean up, since a synchronous request returns the body directly and the truncated read still reports {ok, Body} (#918). The same applies to a failed body read and to bodyless (204/304) responses.
  • hackney_conn:get_location/1 and set_location/2 no longer exit with noproc when the connection has already stopped, which would otherwise propagate out of hackney:request/5 on the redirect path.

Changed

  • Like curl, an empty body on a body-bearing method (POST/PUT/PATCH) now sends Content-Length: 0; bodyless methods (GET/HEAD/DELETE) are unchanged (#917).
  • Update dependencies to their latest releases: quic 1.8.0, webtransport 0.4.4, mimerl 1.5.0, and cowboy 2.18.0 for the test suite.
Source: README.md, updated 2026-08-11