Go HTTP/2 SETTINGS Frame DoS Excessive CPU
CVE-2026-78669 Published on October 8, 2026
Excessive CPU consumption from repeated initial window changes in net/http
A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.
Products Associated with CVE-2026-78669
Want to know whenever a new CVE is published for GoLang Go? stack.watch will email you.
Affected Versions
Go standard library net/http:- Before 1.26.9 is affected.
- Version 1.27.0-0 and below 1.27.2 is affected.
- Before 0.60.0 is affected.