HTTP/2 Server Vulnerability in Go Programming Language by Google
CVE-2026-78663
Currently unrated
What is CVE-2026-78663?
A vulnerability in the Go programming language's HTTP/2 server enables a malicious client to exploit the refunding mechanism of connection-level flow control. The flaw allows a client to reset a stream and receive a refund for the sent but unread data. This process can occur twice, allowing the attacker to bypass the established connection-level flow control limits. Consequently, while total buffered data remains constrained by concurrent stream limits, this loophole poses a significant risk of resource exhaustion and server performance degradation.
Affected Version(s)
golang.org/x/net/http2 0 < 0.60.0
net/http 0 < 1.26.9
net/http/internal/http2 1.27.0-0 < 1.27.2
