CVE-2026-97032
Received Received - Intake

HTTP/2 Server Crash Due to Concurrent HPACK Encoder Modification

Vulnerability report for CVE-2026-97032, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Go standard library net/http 0
Go standard library net/http/internal/http2 1.27.0-0
golang.org/x/net golang.org/x/net/http2 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves HTTP/2 servers crashing due to concurrent modification of the HPACK encoder without proper synchronization. A malicious client can repeatedly send requests while altering the header table size, causing the server to crash during response encoding.

Impact Analysis

If you operate an HTTP/2 server using Go's standard library or golang.org/x/net/http2, a malicious client could exploit this to crash your server repeatedly, leading to denial of service and potential downtime for your services.

Compliance Impact

This vulnerability could lead to denial-of-service (DoS) conditions by crashing HTTP/2 servers, potentially disrupting services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect the availability of systems handling protected health information. However, the specific compliance impact depends on implementation and mitigation measures.

Mitigation Strategies

Update Go to the latest version that patches this issue. Avoid using vulnerable versions of the net/http or http2 packages. Monitor server logs for crashes or unusual activity related to HTTP/2 connections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97032. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart