Go · Golang.Org/X/Net · CVE-2026-78660
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
The HTTP/2 implementation is lax regarding malformed framing-related headers. When acting as a reverse proxy, the system may forward responses containing these malformed headers to an HTTP/1 client. If the client does not strictly validate these headers, it can lead to response smuggling, a technique where an attacker interferes with the way a proxy and a backend server interpret the sequence of HTTP responses.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.