HTTP/2 Framing Vulnerability in Go's Reverse Proxy Implementation
CVE-2026-78660
Currently unrated
What is CVE-2026-78660?
A vulnerability exists in the HTTP/2 implementation of the Go programming language that allows for the forwarding of malformed framing-related headers to HTTP/1 clients. This could potentially lead to response smuggling if the HTTP/1 client does not strictly adhere to header handling protocols. This issue highlights the need for robust validation in HTTP response mechanisms, particularly when serving as a reverse proxy.
Affected Version(s)
golang.org/x/net/http2 0 < 0.60.0
net/http 0 < 1.26.9
net/http/internal/http2 1.27.0-0 < 1.27.2
