CVE-2026-78667 PUBLISHED

Lack of limit on size of parsed Range headers in net/http

Assigner: Go
Reserved: 24.08.2026 Published: 08.10.2026 Updated: 08.10.2026

When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.

Product Status

Vendor Go standard library
Product net/http
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)

Credits

  • Jakub Ciolek (https://ciolek.dev)

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling