Go net/http HTTP/2 Trailer Header Memory Exhaustion
CVE-2026-78659 Published on October 8, 2026
HTTP/2 server memory exhaustion due to Trailer headers in net/http
When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.
Products Associated with CVE-2026-78659
Want to know whenever a new CVE is published for GoLang Go? stack.watch will email you.
Affected Versions
Go standard library net/http:- Before 1.26.9 is affected.
- Version 1.27.0-0 and below 1.27.2 is affected.
- Before 0.60.0 is affected.