PatchSiren cyber security CVE debrief
CVE-2026-78660 Google CVE debrief
The CVE record for CVE-2026-78660 was published on 2026-10-08T22:31:09.000Z. This vulnerability affects the Go net/http package, specifically its HTTP/2 implementation, which has been lax about malformed framing-related headers. This could allow for response smuggling when acting as a reverse proxy for HTTP/1 clients that also do not strictly enforce these headers. Defenders managing Go applications using the net/http package, especially those configured as reverse proxies for HTTP/1 clients, should assess their exposure to this vulnerability and consider updating to patched versions. The NVD entry is currently Unspecified.
- Vendor
- Product
- Go
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders managing Go applications using the net/http package, especially those configured as reverse proxies for HTTP/1 clients, should assess their exposure to this vulnerability and consider updating to patched versions.
Why it matters
CVE-2026-78660 allows for potential response smuggling in Go applications using the net/http package as reverse proxies. Defenders should verify exposure, especially in configurations with lax header enforcement.
- Potential for response smuggling in reverse proxy configurations
- Need for verification of client and server header enforcement
- Possible exposure in HTTP/2 and HTTP/1 interactions
Technical summary
The Go net/http package has historically been lax about malformed framing-related headers in its HTTP/2 implementation. This could allow for response smuggling when acting as a reverse proxy for HTTP/1 clients that also do not strictly enforce these headers. The affected product context includes Go applications using the net/http package as reverse proxies. The defensive impact involves verifying exposure in HTTP/2 and HTTP/1 reverse proxy configurations, especially where client and server implementations may not strictly enforce framing-related headers.
Defensive priority
Defenders should prioritize verifying exposure in HTTP/2 and HTTP/1 reverse proxy configurations, especially where client and server implementations may not strictly enforce framing-related headers.
Recommended defensive actions
- Verify HTTP/2 and HTTP/1 reverse proxy configurations for potential exposure
- Assess client and server implementations for strict enforcement of framing-related headers
- Consider updating to Go versions 1.26.9, 1.27.2, or 0.60.0 for affected packages
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from the Go project indicates that historically, the HTTP/2 implementation in net/http has been lax about malformed framing-related headers. This could allow for response smuggling when acting as a reverse proxy for HTTP/1 clients that also do not strictly enforce these headers.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78660 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78660
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78660 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78660
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
HTTP/2 transport accepts malformed framing-related headers in net/http
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GO-2026-6610.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://go.dev/cl/835145
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://go.dev/cl/836385
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://go.dev/issue/81115
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.