Impact
The HTTP/2 server in Go's net/http and related packages improperly refunds the same data twice—once when a client resets a stream and again when the handler reads buffered data—thereby bypassing the MaxReceiveBufferPerConnection limit. This double refund allows an attacker to cause the server to allocate more memory than intended, leading to uncontrolled memory growth and potential denial of service. The flaw results from incorrect handling of flow‑control credit management and can be triggered by remotely interacting with an HTTP/2 service.
Affected Systems
Any Go application that uses the standard library net/http, the internal HTTP/2 implementation net/http/internal/http2, or the golang.org/x/net/http2 package is affected. All Go distributions containing these packages are vulnerable; the specific version ranges have not been publicly disclosed yet.
Risk and Exploitability
The vulnerability has no publicly available exploit and is not listed in KEV. Its EPSS is currently unavailable, but the design flaw enables a medium‑to‑high risk of denial of service if an attacker can repeatedly reset streams while sending data to an HTTP/2 service. The resulting resource exhaustion could degrade or bring down service availability.
OpenCVE Enrichment