Memory Overhead Vulnerability in HTTP/2 Servers by Go
CVE-2026-78659
Currently unrated
What is CVE-2026-78659?
A vulnerability exists in HTTP/2 servers implemented in Go that allows a malicious client to exploit the handling of 'Trailer' headers. By sending a large number of declared 'Trailer' fields, the client can cause significant memory allocation by bypassing constraints set by Server.MaxHeaderValueCount and Server.MaxHeaderBytes. This manipulation results in potential resource exhaustion, impacting server performance and reliability. It is important to note that this issue does not affect HTTP/1 servers due to different request multiplexing and header calculation methods.
Affected Version(s)
golang.org/x/net/http2 0 < 0.60.0
net/http 0 < 1.26.9
net/http/internal/http2 1.27.0-0 < 1.27.2
