CVE-2026-78669
Received Received - Intake

HTTP/2 DoS via Excessive SETTINGS Frames in Go

Vulnerability report for CVE-2026-78669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Go standard library net/http 0
Go standard library net/http/internal/http2 1.27.0-0
golang.org/x/net golang.org/x/net/http2 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a malicious HTTP/2 peer exploiting a flaw where opening many streams and sending numerous small SETTINGS frames with SETTINGS_INITIAL_WINDOW_SIZE values causes excessive CPU consumption on the client or server.

Detection Guidance

This vulnerability involves HTTP/2 SETTINGS frames causing CPU exhaustion. Monitor for unusual numbers of HTTP/2 streams or SETTINGS frames using network tools like Wireshark or tcpdump. Check Go application logs for high CPU usage during HTTP/2 traffic.

Impact Analysis

This vulnerability can lead to degraded performance or denial of service by consuming excessive CPU resources on affected systems, potentially slowing down or crashing applications using HTTP/2.

Mitigation Strategies

Update Go to version 1.22.7 or later, which includes fixes for this HTTP/2 vulnerability. Monitor network traffic for unusual SETTINGS frame patterns or excessive stream openings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart