Impact
A race condition exists in the Go HTTP/2 implementation where the HPACK encoder can be accessed concurrently by two goroutines without proper synchronization. One goroutine encodes HEADERS frames as part of a response, while another goroutine updates the encoder’s table size when handling a SETTINGS frame that contains SETTINGS_HEADER_TABLE_SIZE. A malicious client can repeatedly send these SETTINGS frames while the server is encoding a response, causing the server to crash. The crash results in a denial of service because the server process terminates when the fault occurs.
Affected Systems
The vulnerability affects Go’s standard library packages net/http, net/http/internal/http2, and the golang.org/x/net/http2 module. No specific version range is specified, indicating that any Go release containing these packages prior to the fix could be impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in CISA KEV. The flaw can be triggered over a normal network connection to any HTTP/2 enabled server that uses the affected Go packages. A client capable of sending the relevant SETTINGS frames can cause the server to crash whenever the race occurs.
OpenCVE Enrichment