CVE-2026-78659 PUBLISHED

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Assigner: Go
Reserved: 24.08.2026 Published: 08.10.2026 Updated: 09.10.2026

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.

Product Status

Vendor Go standard library
Product net/http
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
Vendor Go standard library
Product net/http/internal/http2
Versions Default: unaffected
  • affected from 1.27.0-0 to 1.27.2 (excl.)
Vendor golang.org/x/net
Product golang.org/x/net/http2
Versions Default: unaffected
  • affected from 0 to 0.60.0 (excl.)

Credits

  • RyotaK (https://ryotak.net) of GMO Flatt Security Inc.

References

Problem Types

  • CWE-405: Asymmetric Resource Consumption (Amplification)