CVE-2026-78659
Received Received - Intake

Memory Exhaustion via Trailer Headers in Go HTTP Server

Vulnerability report for CVE-2026-78659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Go standard library net/http 0
Go standard library net/http/internal/http2 1.27.0-0
golang.org/x/net golang.org/x/net/http2 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a memory exhaustion attack in HTTP/2 servers using Go's standard library. A malicious client sends a 'Trailer' header declaring many fields, causing the server to allocate excessive memory. This bypasses normal header size limits because the overhead is tied to the number of fields rather than their total size.

Detection Guidance

This vulnerability primarily affects HTTP/2 servers using Go's standard library or golang.org/x/net/http2. To detect it, monitor for unusually high memory usage on your HTTP/2 servers, especially when handling requests with Trailer headers. Check server logs for requests with excessive Trailer headers. Use tools like netstat or ss to inspect active HTTP/2 connections and their memory consumption patterns.

Impact Analysis

If you operate an HTTP/2 server using Go's net/http or golang.org/x/net/http2 libraries, this flaw could allow attackers to crash your server or degrade performance by consuming excessive memory. HTTP/1 servers are not affected.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a resource exhaustion issue in HTTP/2 servers. However, if exploited, it could lead to denial-of-service conditions, potentially impacting availability requirements under these regulations.

Mitigation Strategies

Immediately update your Go version to the latest stable release, as patches for this issue are expected to be included in future updates. For HTTP/2 servers, consider disabling HTTP/2 support temporarily if possible. Implement rate limiting to restrict the number of requests with Trailer headers. Monitor server memory usage closely and set up alerts for abnormal spikes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart