PT-2026-108322 · Go+2 · Golang.Org/X/Net+4

·

CVE-2026-97032

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description HTTP/2 servers may crash due to concurrent modification of the HPACK encoder. This occurs when the server modifies the encoder from two goroutines without synchronization: one encoding a HEADERS frame for a client response, and another modifying the encoder table size while processing a SETTINGS frame containing SETTINGS HEADER TABLE SIZE sent by a client. A malicious actor can trigger this crash by repeatedly sending requests while simultaneously changing the header table size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97032
GO-2026-6617

Affected Products

Golang.Org/X/Net
Golang.Org/X/Net/Http2
Net/Http
Net/Http/Internal/Http2
Stdlib