长期以来,我们在 HTTP/2 实现中对格式错误的、与帧相关的头部(framing-related headers)的处理较为宽松,因为这些头部不会影响 HTTP/2 帧的正常行为。然而,这种行为会导致当我们的实现作为反向代理使用时,可能将这些包含格式错误帧相关头部的响应转发给 HTTP/1 客户端。如果该 HTTP/1 客户端自身对头部的解析也不够严格,就可能引发响应走私(response smuggling)漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Go standard library | net/http | 0 ~ 1.26.9 | - |
|
| Go standard library | net/http/internal/http2 | 1.27.0-0 ~ 1.27.2 | - |
|
| golang.org/x/net | golang.org/x/net/http2 | 0 ~ 0.60.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94439 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http | |
| CVE-2026-94440 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart | |
| CVE-2026-94448 | Reset context tracking on consecutive template expressions in html/template | |
| CVE-2026-56857 | Root.Mkdir(All) can follow junctions out of the root on Windows in os | |
| CVE-2026-56866 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http | |
| CVE-2026-78659 | HTTP/2 server memory exhaustion due to Trailer headers in net/http | |
| CVE-2026-78663 | Double flow control refund on HTTP/2 server streams in net/http | |
| CVE-2026-78667 | Lack of limit on size of parsed Range headers in net/http | |
| CVE-2026-78669 | Excessive CPU consumption from repeated initial window changes in net/http | |
| CVE-2026-97032 | HTTP/2 server crash due to HPACK encoder race in net/http | |
| CVE-2026-97030 | Recognize yield as regexp preceder keyword in html/template | |
| CVE-2026-97031 | Reject malformed ECH outer extension references in crypto/tls |
No comments yet