Vulnerability GO-2026-6603

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
HTTP/2 server memory exhaustion due to Trailer headers in net/http
v0.1.0 - v0.59.0
v0.1.0 - v0.59.0

Summary

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Details

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.

Timeline

Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 10:45 PM UTC