HTTP/2 服务器可能因并发修改其 HPACK 编码器而崩溃。问题的原因是服务器从两个 goroutine 中未经同步地修改 HPACK 编码器:其中一个 goroutine 在响应客户端时,使用编码器对 HEADERS 帧进行编码;另一个 goroutine 在处理客户端发送的包含 SETTINGS_HEADER_TABLE_SIZE 设置的 SETTINGS 帧时,修改编码器的表大小。恶意客户端可通过反复发送请求并不断更改头部表大小,导致服务器崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Go standard library | net/http | 0 ~ 1.26.9 | - |
|
| Go standard library | net/http/internal/http2 | 1.27.0-0 ~ 1.27.2 | - |
|
| golang.org/x/net | golang.org/x/net/http2 | 0 ~ 0.60.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94439 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http | |
| CVE-2026-94440 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart | |
| CVE-2026-94448 | Reset context tracking on consecutive template expressions in html/template | |
| CVE-2026-56857 | Root.Mkdir(All) can follow junctions out of the root on Windows in os | |
| CVE-2026-56866 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http | |
| CVE-2026-78659 | HTTP/2 server memory exhaustion due to Trailer headers in net/http | |
| CVE-2026-78660 | HTTP/2 transport accepts malformed framing-related headers in net/http | |
| CVE-2026-78663 | Double flow control refund on HTTP/2 server streams in net/http | |
| CVE-2026-78667 | Lack of limit on size of parsed Range headers in net/http | |
| CVE-2026-78669 | Excessive CPU consumption from repeated initial window changes in net/http | |
| CVE-2026-97030 | Recognize yield as regexp preceder keyword in html/template | |
| CVE-2026-97031 | Reject malformed ECH outer extension references in crypto/tls |
No comments yet