CVE-2026-78669 PUBLISHED

Excessive CPU consumption from repeated initial window changes in net/http

Assigner: Go
Reserved: 24.08.2026 Published: 08.10.2026 Updated: 08.10.2026

A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.

Product Status

Vendor Go standard library
Product net/http
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
Vendor Go standard library
Product net/http/internal/http2
Versions Default: unaffected
  • affected from 1.27.0-0 to 1.27.2 (excl.)
Vendor golang.org/x/net
Product golang.org/x/net/http2
Versions Default: unaffected
  • affected from 0 to 0.60.0 (excl.)

Credits

  • Jakub Ciolek (https://ciolek.dev)

References

Problem Types

  • CWE-405: Asymmetric Resource Consumption (Amplification)