Vulnerability GO-2026-6089

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 09:43 PM UTC
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
<1.25.13
<1.25.13

Summary

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

Details

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

Impacted packages

Timeline

Published
1 month ago
August 13, 2026 at 09:43 PM UTC
Last Modified
4 days ago
September 24, 2026 at 10:41 AM UTC