PT-2026-108322 · Go+2 · Golang.Org/X/Net+4
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
HTTP/2 servers may crash due to concurrent modification of the HPACK encoder. This occurs when the server modifies the encoder from two goroutines without synchronization: one encoding a HEADERS frame for a client response, and another modifying the encoder table size while processing a SETTINGS frame containing
SETTINGS HEADER TABLE SIZE sent by a client. A malicious actor can trigger this crash by repeatedly sending requests while simultaneously changing the header table size.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Golang.Org/X/Net
Golang.Org/X/Net/Http2
Net/Http
Net/Http/Internal/Http2
Stdlib