Vulnerability GO-2026-6610

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
HTTP/2 transport accepts malformed framing-related headers in net/http
v0.1.0 - v0.59.0
v0.1.0 - v0.59.0

Summary

HTTP/2 transport accepts malformed framing-related headers in net/http

Details

Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.

Timeline

Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 11:00 PM UTC