Impact
A malicious HTTP/2 peer can exhaust a client or server’s CPU by opening many streams and repeatedly sending small SETTINGS frames that alter the SETTINGS_INITIAL_WINDOW_SIZE. The result is a significant increase in processing load without advancing data transfer, effectively denying service. The weakness is a form of resource‑consumption abuse commonly categorized as an uncontrolled resource consumption flaw.
Affected Systems
Go’s standard library packages net/http, net/http/internal/http2, and the golang.org/x/net/http2 package are affected. No specific version ranges are listed, so any deployment using these packages may be susceptible.
Risk and Exploitability
Because the vulnerability is triggered by crafted HTTP/2 traffic, the attack vector is network. No EPSS score is available and the vulnerability is not in the CISA KEV catalog, but the absence of a public scoring does not imply low risk. Deployments that rely on HTTP/2 for client‑server communication could experience sudden CPU spikes if an attacker opens many streams or injects frequent SETTINGS frames. More detailed risk assessment should consider whether HTTP/2 is enabled and whether external traffic is restricted. The impact is potentially high, especially in environments where service availability is critical.
OpenCVE Enrichment