Description
When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Update Go
AI Analysis

Impact

The vulnerability lies in the Go net/http package’s handling of the HTTP Range header. When a request contains a large number of small ranges, the server parses them all, consuming excessive CPU time. The absence of a limit means an attacker can craft a request that forces the server to perform a large amount of work, potentially exhausting available CPU cycles. This flaw does not grant code execution or data disclosure; its effect is limited to service availability loss due to resource exhaustion.

Affected Systems

All applications built with the Go standard library, specifically those that use FileServer, ServeContent or ServeFile functions, are affected. The vulnerability applies to any server or service that accepts Range headers via net/http. No particular Go release is specified, so any version prior to the fix that includes the unbounded parsing logic is potentially impacted.

Risk and Exploitability

The CVSS score is not provided, and the Exploit Prediction Scoring System value is not available. The vulnerability is not listed in CISA’s KEV catalogue. Attackers can exploit it by sending HTTP requests with a Range header containing a large number of small ranges, which forces the server to iterate over each range and thus increase CPU usage. Because the flaw lies in input parsing, the attack can be performed remotely over the network without privileged access. The lack of proactive limits makes the vulnerability moderately easy to exploit, presenting a low to moderate risk in absence of mitigation.

Generated by OpenCVE AI on October 9, 2026 at 00:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Go runtime and standard library to the latest stable release where the Range header parsing limits have been introduced, such as Go 1.22 or newer.
  • If upgrading Go is not immediately possible, deploy a reverse proxy or load balancer in front of the application that limits the size of the Range header or rejects requests containing more than a configurable number of ranges to protect against CPU exhaustion.
  • In Go applications that need to serve static files, consider disabling Range header support for non‑essential services or replace the default net/http handlers with custom handlers that enforce a strict limit on the number of ranges processed.

Generated by OpenCVE AI on October 9, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library net/http
Vendors & Products Go Standard Library
Go Standard Library net/http

Fri, 09 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.
Title Lack of limit on size of parsed Range headers in net/http
References

Subscriptions

Go Standard Library Net/http
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:59.148Z

Reserved: 2026-08-24T23:36:15.738Z

Link: CVE-2026-78667

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:03.880

Modified: 2026-10-08T23:17:03.880

Link: CVE-2026-78667

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-08T22:53:59Z

Links: CVE-2026-78667 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:15:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling