PT-2026-108311 · Go+2 · Golang.Org/X/Net+4

·

CVE-2026-78660

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The HTTP/2 implementation is lax regarding malformed framing-related headers. When acting as a reverse proxy, the system may forward responses containing these malformed headers to an HTTP/1 client. If the client does not strictly validate these headers, it can lead to response smuggling, a technique where an attacker interferes with the way a proxy and a backend server interpret the sequence of HTTP responses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-78660
GO-2026-6610

Affected Products

Golang.Org/X/Net
Golang.Org/X/Net/Http2
Net/Http
Net/Http/Internal/Http2
Stdlib