HTTP/2 Framing Vulnerability in Go's Reverse Proxy Implementation
CVE-2026-78660

Currently unrated

What is CVE-2026-78660?

A vulnerability exists in the HTTP/2 implementation of the Go programming language that allows for the forwarding of malformed framing-related headers to HTTP/1 clients. This could potentially lead to response smuggling if the HTTP/1 client does not strictly adhere to header handling protocols. This issue highlights the need for robust validation in HTTP response mechanisms, particularly when serving as a reverse proxy.

Affected Version(s)

golang.org/x/net/http2 0 < 0.60.0

net/http 0 < 1.26.9

net/http/internal/http2 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TJ Barton
.