PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78663 Go CVE debrief

A vulnerability in the Go standard library's HTTP/2 server implementation allows a malicious client to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection) by exploiting a double refund of connection-level flow control for the same data. This can occur when a client resets a stream and the request handler reads the buffered data.

Vendor
Go
Product
stdlib
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Go-based HTTP/2 server deployments, especially those with custom configurations, should assess exposure and prioritize verification and remediation efforts.

Why it matters

CVE-2026-78663 allows a malicious client to bypass flow control limits in Go's HTTP/2 server implementation, potentially leading to increased resource utilization or denial of service conditions. Defenders should prioritize verifying exposure, especially in custom or non-default configurations, and apply available patches or compensating controls.

  • Potential bypass of configured connection-level flow control limits
  • Possible increase in resource utilization or denial of service conditions
  • Need for verification of exposure in custom or non-default configurations
  • Priority for applying available patches or compensating controls

Technical summary

The HTTP/2 server can refund connection-level flow control twice for the same data: once when a client resets a stream and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). This vulnerability is confirmed in Go versions prior to 1.26.9 and 1.27.2, with official fixes available in these versions. The double refund can occur when a client resets a stream and the request handler reads the buffered data, potentially leading to increased resource utilization or denial of service conditions.

Defensive priority

Defenders should prioritize verifying exposure in HTTP/2 server deployments, especially those with custom configurations or non-default MaxReceiveBufferPerConnection settings, and assess the need for updates or compensating controls.

Recommended defensive actions

  • Verify and apply the available patches or updates for the Go standard library
  • Review and adjust HTTP/2 server configurations, especially MaxReceiveBufferPerConnection settings
  • Monitor for unusual traffic patterns or client behavior indicative of exploitation attempts
  • Perform an inventory of assets using affected versions of the Go standard library
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Consider implementing additional monitoring for HTTP/2 server activity

Evidence notes

The vulnerability is confirmed in Go versions prior to 1.26.9 and 1.27.2. Official fixes are available in these versions. The CVE Program and NVD provide additional details. Evidence is limited to public sources and may not be comprehensive. Defenders should verify exposure in their specific environments, especially for custom or non-default configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78663 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78663

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78663 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78663

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Double flow control refund on HTTP/2 server streams in net/http

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GO-2026-6612.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://go.dev/cl/847187

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://go.dev/cl/847310

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://go.dev/issue/81743

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.