CPU Resource Exhaustion Vulnerability in FileServer Component of Go
CVE-2026-78667

Currently unrated

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-78667?

The FileServer component of the Go programming language is susceptible to a vulnerability arising from the improper handling of Range headers containing multiple small ranges. This flaw may lead to excessive CPU resource consumption, potentially affecting server performance and responsiveness during high load scenarios.

Affected Version(s)

net/http 0 < 1.26.9

net/http 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Ciolek (https://ciolek.dev)
.