PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78660 Google CVE debrief

The CVE record for CVE-2026-78660 was published on 2026-10-08T22:31:09.000Z. This vulnerability affects the Go net/http package, specifically its HTTP/2 implementation, which has been lax about malformed framing-related headers. This could allow for response smuggling when acting as a reverse proxy for HTTP/1 clients that also do not strictly enforce these headers. Defenders managing Go applications using the net/http package, especially those configured as reverse proxies for HTTP/1 clients, should assess their exposure to this vulnerability and consider updating to patched versions. The NVD entry is currently Unspecified.

Vendor
Google
Product
Go
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders managing Go applications using the net/http package, especially those configured as reverse proxies for HTTP/1 clients, should assess their exposure to this vulnerability and consider updating to patched versions.

Why it matters

CVE-2026-78660 allows for potential response smuggling in Go applications using the net/http package as reverse proxies. Defenders should verify exposure, especially in configurations with lax header enforcement.

  • Potential for response smuggling in reverse proxy configurations
  • Need for verification of client and server header enforcement
  • Possible exposure in HTTP/2 and HTTP/1 interactions

Technical summary

The Go net/http package has historically been lax about malformed framing-related headers in its HTTP/2 implementation. This could allow for response smuggling when acting as a reverse proxy for HTTP/1 clients that also do not strictly enforce these headers. The affected product context includes Go applications using the net/http package as reverse proxies. The defensive impact involves verifying exposure in HTTP/2 and HTTP/1 reverse proxy configurations, especially where client and server implementations may not strictly enforce framing-related headers.

Defensive priority

Defenders should prioritize verifying exposure in HTTP/2 and HTTP/1 reverse proxy configurations, especially where client and server implementations may not strictly enforce framing-related headers.

Recommended defensive actions

  • Verify HTTP/2 and HTTP/1 reverse proxy configurations for potential exposure
  • Assess client and server implementations for strict enforcement of framing-related headers
  • Consider updating to Go versions 1.26.9, 1.27.2, or 0.60.0 for affected packages
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from the Go project indicates that historically, the HTTP/2 implementation in net/http has been lax about malformed framing-related headers. This could allow for response smuggling when acting as a reverse proxy for HTTP/1 clients that also do not strictly enforce these headers.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78660 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78660

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78660 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78660

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.