Description
Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Response smuggling via malformed HTTP/2 headers
Action: Apply patch
AI Analysis

Impact

This vulnerability resides in the Go HTTP/2 implementation. The framework allows malformed framing‑related headers because they cannot corrupt the HTTP/2 framing itself. When acting as a reverse proxy, the implementation forwards such headers to an HTTP/1 client. If that downstream client accepts the headers without strict validation, an attacker can craft responses that are split or merged in the HTTP/1 stream, leading to response smuggling. The flaw results from insufficient input validation (CWE‑20). The attacker can inject arbitrary data into the response, exposing confidential information or manipulating application behavior. The likely attack vector is an attacker sending a malicious HTTP/2 request with malformed framing‑related headers to a reverse proxy that forwards to an HTTP/1 client.

Affected Systems

The affected components are Go’s net/http, net/http/internal/http2, and golang.org/x/net/http2 packages. All Go releases compiled with these packages prior to the referenced fixes are vulnerable. No explicit version list is provided in the advisory.

Risk and Exploitability

The issue can be exploited only when an attacker can inject malformed headers into an HTTP/2 request that is then proxied to an HTTP/1 client and that client is permissive to header parsing. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the exploit requires a specific proxy configuration and a vulnerable downstream client, so the likelihood of exploitation is low to moderate; however, the impact of a successful smuggle can be significant.

Generated by OpenCVE AI on October 9, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Go release that includes the fix referenced in the advisory
  • an upgrade is not immediately possible, disable HTTP/2 proxying or configure the proxy to strip framing‑related headers before forwarding
  • Ensure downstream HTTP/1 clients enforce strict header validation to prevent response smuggling

Generated by OpenCVE AI on October 9, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.
Title HTTP/2 transport accepts malformed framing-related headers in net/http
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:59.334Z

Reserved: 2026-08-24T23:36:15.738Z

Link: CVE-2026-78660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:03.510

Modified: 2026-10-08T23:17:03.510

Link: CVE-2026-78660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T02:00:23Z

Weaknesses
  • CWE-20

    Improper Input Validation