Concurrency Issue in HTTP/2 Servers Affects Go Programming Language
CVE-2026-97032

Currently unrated

What is CVE-2026-97032?

An identified issue in HTTP/2 servers within the Go programming language involves a concurrency flaw in the HPACK encoder. This vulnerability arises when the server processes encoding for a HEADERS frame simultaneously with modifications to the header table size. A malicious client can exploit this by sending requests that alter the SETTINGS_HEADER_TABLE_SIZE, leading to server crashes. Proper synchronization mechanisms in the encoder are crucial to mitigate this vulnerability and ensure robust server performance.

Affected Version(s)

golang.org/x/net/http2 0 < 0.60.0

net/http 0 < 1.26.9

net/http/internal/http2 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RyotaK (https://ryotak.net) of GMO Flatt Security Inc.
.