Concurrency Issue in HTTP/2 Servers Affects Go Programming Language
CVE-2026-97032
Currently unrated
What is CVE-2026-97032?
An identified issue in HTTP/2 servers within the Go programming language involves a concurrency flaw in the HPACK encoder. This vulnerability arises when the server processes encoding for a HEADERS frame simultaneously with modifications to the header table size. A malicious client can exploit this by sending requests that alter the SETTINGS_HEADER_TABLE_SIZE, leading to server crashes. Proper synchronization mechanisms in the encoder are crucial to mitigate this vulnerability and ensure robust server performance.
Affected Version(s)
golang.org/x/net/http2 0 < 0.60.0
net/http 0 < 1.26.9
net/http/internal/http2 1.27.0-0 < 1.27.2
