freenode
Languages & Toolchains

Go x/net 0.60.0 patches HTTP/2 memory and CPU exhaustion flaws

Three server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.

The Go project has released golang.org/x/net v0.60.0 to fix three HTTP/2 security issues that could let a remote peer exhaust memory or CPU, or exceed configured flow-control limits.

CVE-2026-78659 covers a memory-exhaustion path on HTTP/2 servers. When a client sends a Trailer header that names a large number of fields, the server builds a Request.Trailer map entry for each one. Those allocations bypassed Server.MaxHeaderValueCount and Server.MaxHeaderBytes, so a single multiplexed connection could force disproportionate memory use. The limits now cover declared trailer fields as well. The issue does not affect HTTP/1 servers. RyotaK of GMO Flatt Security Inc. reported it.

CVE-2026-78669 addresses excessive CPU use. A peer could open many streams and flood the connection with small SETTINGS frames that repeatedly change SETTINGS_INITIAL_WINDOW_SIZE. Both client and server now apply those window-size updates in constant time rather than walking every open stream. Jakub Ciolek reported the problem.

A third fix closes a double flow-control refund on the server. After a client reset a stream, the server could credit the same unread data twice, once on reset and again when the handler later read the buffered body, letting an attacker exceed MaxReceiveBufferPerConnection.

Operators running HTTP/2 servers or clients that depend on x/net should upgrade to v0.60.0.