Description
The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Resource exhaustion via double flow‑control refund
Action: Immediate Patch
AI Analysis

Impact

The HTTP/2 server in Go's net/http and related packages improperly refunds the same data twice—once when a client resets a stream and again when the handler reads buffered data—thereby bypassing the MaxReceiveBufferPerConnection limit. This double refund allows an attacker to cause the server to allocate more memory than intended, leading to uncontrolled memory growth and potential denial of service. The flaw results from incorrect handling of flow‑control credit management and can be triggered by remotely interacting with an HTTP/2 service.

Affected Systems

Any Go application that uses the standard library net/http, the internal HTTP/2 implementation net/http/internal/http2, or the golang.org/x/net/http2 package is affected. All Go distributions containing these packages are vulnerable; the specific version ranges have not been publicly disclosed yet.

Risk and Exploitability

The vulnerability has no publicly available exploit and is not listed in KEV. Its EPSS is currently unavailable, but the design flaw enables a medium‑to‑high risk of denial of service if an attacker can repeatedly reset streams while sending data to an HTTP/2 service. The resulting resource exhaustion could degrade or bring down service availability.

Generated by OpenCVE AI on October 9, 2026 at 01:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Go release that includes the fix referenced in Go issue 81743.
  • If an upgrade is not possible immediately, disable HTTP/2 on the server or reduce the MaxReceiveBufferPerConnection setting and monitor for abnormal reset patterns.
  • Implement application‑level checks to detect and rate‑limit excessive stream reset activity and to log unusually large buffered data volumes.

Generated by OpenCVE AI on October 9, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Title Double flow control refund on HTTP/2 server streams in net/http
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:59.772Z

Reserved: 2026-08-24T23:36:15.738Z

Link: CVE-2026-78663

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:03.647

Modified: 2026-10-08T23:17:03.647

Link: CVE-2026-78663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:30:18Z

Weaknesses