PatchSiren cyber security CVE debrief
CVE-2026-78663 Go CVE debrief
A vulnerability in the Go standard library's HTTP/2 server implementation allows a malicious client to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection) by exploiting a double refund of connection-level flow control for the same data. This can occur when a client resets a stream and the request handler reads the buffered data.
- Vendor
- Go
- Product
- stdlib
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Go-based HTTP/2 server deployments, especially those with custom configurations, should assess exposure and prioritize verification and remediation efforts.
Why it matters
CVE-2026-78663 allows a malicious client to bypass flow control limits in Go's HTTP/2 server implementation, potentially leading to increased resource utilization or denial of service conditions. Defenders should prioritize verifying exposure, especially in custom or non-default configurations, and apply available patches or compensating controls.
- Potential bypass of configured connection-level flow control limits
- Possible increase in resource utilization or denial of service conditions
- Need for verification of exposure in custom or non-default configurations
- Priority for applying available patches or compensating controls
Technical summary
The HTTP/2 server can refund connection-level flow control twice for the same data: once when a client resets a stream and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). This vulnerability is confirmed in Go versions prior to 1.26.9 and 1.27.2, with official fixes available in these versions. The double refund can occur when a client resets a stream and the request handler reads the buffered data, potentially leading to increased resource utilization or denial of service conditions.
Defensive priority
Defenders should prioritize verifying exposure in HTTP/2 server deployments, especially those with custom configurations or non-default MaxReceiveBufferPerConnection settings, and assess the need for updates or compensating controls.
Recommended defensive actions
- Verify and apply the available patches or updates for the Go standard library
- Review and adjust HTTP/2 server configurations, especially MaxReceiveBufferPerConnection settings
- Monitor for unusual traffic patterns or client behavior indicative of exploitation attempts
- Perform an inventory of assets using affected versions of the Go standard library
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Consider implementing additional monitoring for HTTP/2 server activity
Evidence notes
The vulnerability is confirmed in Go versions prior to 1.26.9 and 1.27.2. Official fixes are available in these versions. The CVE Program and NVD provide additional details. Evidence is limited to public sources and may not be comprehensive. Defenders should verify exposure in their specific environments, especially for custom or non-default configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78663 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78663
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78663 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78663
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Double flow control refund on HTTP/2 server streams in net/http
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GO-2026-6612.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://go.dev/cl/847187
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://go.dev/cl/847310
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://go.dev/issue/81743
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.