当客户端发送“Trailer”头时,HTTP 服务器会使用这些头值填充传递给服务器处理程序的 Request.Trailer 映射(map)。由于 Request.Trailer 是一个映射,每个条目都会带来额外的内存开销。对于 HTTP/2 服务器,恶意客户端可以通过发送一个声明大量字段的“Trailer”头来利用此问题,导致服务器分配不成比例的内存,同时绕过 Server.MaxHeaderValueCount 和 Server.MaxHeaderBytes 的限制。此漏洞不适用于 HTTP/1 服务器,因为它
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Go standard library | net/http | 0 ~ 1.26.9 | - |
|
| Go standard library | net/http/internal/http2 | 1.27.0-0 ~ 1.27.2 | - |
|
| golang.org/x/net | golang.org/x/net/http2 | 0 ~ 0.60.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94439 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http | |
| CVE-2026-94440 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart | |
| CVE-2026-94448 | Reset context tracking on consecutive template expressions in html/template | |
| CVE-2026-56857 | Root.Mkdir(All) can follow junctions out of the root on Windows in os | |
| CVE-2026-56866 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http | |
| CVE-2026-78660 | HTTP/2 transport accepts malformed framing-related headers in net/http | |
| CVE-2026-78663 | Double flow control refund on HTTP/2 server streams in net/http | |
| CVE-2026-78667 | Lack of limit on size of parsed Range headers in net/http | |
| CVE-2026-78669 | Excessive CPU consumption from repeated initial window changes in net/http | |
| CVE-2026-97032 | HTTP/2 server crash due to HPACK encoder race in net/http | |
| CVE-2026-97030 | Recognize yield as regexp preceder keyword in html/template | |
| CVE-2026-97031 | Reject malformed ECH outer extension references in crypto/tls |
No comments yet