Memory Overhead Vulnerability in HTTP/2 Servers by Go
CVE-2026-78659

Currently unrated

What is CVE-2026-78659?

A vulnerability exists in HTTP/2 servers implemented in Go that allows a malicious client to exploit the handling of 'Trailer' headers. By sending a large number of declared 'Trailer' fields, the client can cause significant memory allocation by bypassing constraints set by Server.MaxHeaderValueCount and Server.MaxHeaderBytes. This manipulation results in potential resource exhaustion, impacting server performance and reliability. It is important to note that this issue does not affect HTTP/1 servers due to different request multiplexing and header calculation methods.

Affected Version(s)

golang.org/x/net/http2 0 < 0.60.0

net/http 0 < 1.26.9

net/http/internal/http2 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RyotaK (https://ryotak.net) of GMO Flatt Security Inc.
.