Impact
When a client sends a Trailer header, the Go HTTP server uses those header values to fill the Request.Trailer map that is passed to the handler. Because the map stores each entry, adding many trailers results in per‑entry memory overhead. An attacker can send a Trailer header that declares an excessive number of fields, causing the server to allocate far more memory than intended and bypass the Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits that normally restrain header size. The excessive allocation can exhaust available memory, leading to application failure or degraded performance, and effectively triggers a denial of service. The described weakness is consistent with a resource‑exhaustion flaw.
Affected Systems
This issue affects any Go application that uses the standard library packages net/http, net/http/internal/http2, or golang.org/x/net/http2 and runs an HTTP/2 server. No specific version was listed, so all versions until the patch are potentially vulnerable.
Risk and Exploitability
The vulnerability can be exploited by any network client that has access to an HTTP/2 endpoint. It does not apply to HTTP/1 servers, as they do not support the same multiplexing of requests and calculate limits differently. Because no EPSS score is available and the issue is not listed in CISA’s KEV catalog, the probability of exploitation in the wild is uncertain, but the potential impact is high if the attack succeeds. The lack of built‑in limits makes the exploitation straightforward for an attacker who can send a large number of trailer fields over a single connection.
OpenCVE Enrichment