Vulnerability GO-2026-6611

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
Excessive CPU consumption from repeated initial window changes in net/http
v0.1.0 - v0.59.0
v0.1.0 - v0.59.0

Summary

Excessive CPU consumption from repeated initial window changes in net/http

Details

A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.

Timeline

Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 10:45 PM UTC