Go HTTP/2 SETTINGS Frame DoS Excessive CPU
CVE-2026-78669 Published on October 8, 2026

Excessive CPU consumption from repeated initial window changes in net/http
A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.

NVD


Products Associated with CVE-2026-78669

Want to know whenever a new CVE is published for GoLang Go? stack.watch will email you.

 

Affected Versions

Go standard library net/http: Go standard library net/http/internal/http2: golang.org/x/net/http2: