Description
A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service via excessive CPU usage
Action: Immediate Patch
AI Analysis

Impact

A malicious HTTP/2 peer can exhaust a client or server’s CPU by opening many streams and repeatedly sending small SETTINGS frames that alter the SETTINGS_INITIAL_WINDOW_SIZE. The result is a significant increase in processing load without advancing data transfer, effectively denying service. The weakness is a form of resource‑consumption abuse commonly categorized as an uncontrolled resource consumption flaw.

Affected Systems

Go’s standard library packages net/http, net/http/internal/http2, and the golang.org/x/net/http2 package are affected. No specific version ranges are listed, so any deployment using these packages may be susceptible.

Risk and Exploitability

Because the vulnerability is triggered by crafted HTTP/2 traffic, the attack vector is network. No EPSS score is available and the vulnerability is not in the CISA KEV catalog, but the absence of a public scoring does not imply low risk. Deployments that rely on HTTP/2 for client‑server communication could experience sudden CPU spikes if an attacker opens many streams or injects frequent SETTINGS frames. More detailed risk assessment should consider whether HTTP/2 is enabled and whether external traffic is restricted. The impact is potentially high, especially in environments where service availability is critical.

Generated by OpenCVE AI on October 9, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Go release that includes the fix referenced by the Go issue and code reviews (e.g., the changes introduced in commits https://go.dev/cl/847186 and https://go.dev/cl/847308).
  • If the application does not require HTTP/2, disable the protocol on servers by setting the appropriate configuration flag or API call to prevent the vulnerability from being exploitable.
  • Implement rate limiting or filtering of HTTP/2 SETTINGS frames at the network or application layer to mitigate the uncontrolled resource consumption reflected by CWE‑400.

Generated by OpenCVE AI on October 9, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.
Title Excessive CPU consumption from repeated initial window changes in net/http
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:59.530Z

Reserved: 2026-08-24T23:36:15.739Z

Link: CVE-2026-78669

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:04.010

Modified: 2026-10-08T23:17:04.010

Link: CVE-2026-78669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T00:30:17Z

Weaknesses

No weakness.