CVE-2026-78663 PUBLISHED

Double flow control refund on HTTP/2 server streams in net/http

Assigner: Go
Reserved: 24.08.2026 Published: 08.10.2026 Updated: 08.10.2026

The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.

Product Status

Vendor Go standard library
Product net/http
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
Vendor Go standard library
Product net/http/internal/http2
Versions Default: unaffected
  • affected from 1.27.0-0 to 1.27.2 (excl.)
Vendor golang.org/x/net
Product golang.org/x/net/http2
Versions Default: unaffected
  • affected from 0 to 0.60.0 (excl.)

Credits

  • Ali Sherif (https://www.linkedin.com/in/ali-sherif-13812b276/)

References

Problem Types

  • CWE-675: Multiple Operations on Resource in Single-Operation Context