Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-399 CWE-770 |
Fri, 09 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-405 | |
| Metrics |
cvssV3_1
|
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go Standard Library
Go Standard Library net/http Go Standard Library net/http2 |
|
| Vendors & Products |
Go Standard Library
Go Standard Library net/http Go Standard Library net/http2 |
Fri, 09 Oct 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-399 CWE-770 |
Thu, 08 Oct 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently. | |
| Title | HTTP/2 server memory exhaustion due to Trailer headers in net/http | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-10-09T15:34:24.199Z
Reserved: 2026-08-24T23:36:03.109Z
Link: CVE-2026-78659
Updated: 2026-10-09T15:27:26.255Z
Status : Awaiting Analysis
Published: 2026-10-08T23:17:03.270
Modified: 2026-10-09T16:35:35.900
Link: CVE-2026-78659
No data.
OpenCVE Enrichment
Updated: 2026-10-09T18:15:08Z
-
CWE-405
Asymmetric Resource Consumption (Amplification)