HTTP/2 Server Vulnerability in Go Programming Language by Google
CVE-2026-78663

Currently unrated

What is CVE-2026-78663?

A vulnerability in the Go programming language's HTTP/2 server enables a malicious client to exploit the refunding mechanism of connection-level flow control. The flaw allows a client to reset a stream and receive a refund for the sent but unread data. This process can occur twice, allowing the attacker to bypass the established connection-level flow control limits. Consequently, while total buffered data remains constrained by concurrent stream limits, this loophole poses a significant risk of resource exhaustion and server performance degradation.

Affected Version(s)

golang.org/x/net/http2 0 < 0.60.0

net/http 0 < 1.26.9

net/http/internal/http2 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)
.