CVE-2026-78659: HTTP/2 server memory exhaustion due to Trailer headers in net/http
When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.
Affected Software
Event History
Frequently Asked Questions
Which server deployments are exposed to this issue?
HTTP/2 servers using Go's net/http are exposed. HTTP/1 servers are not affected by this exploit because they cannot multiplex a large number of requests over one TCP connection and calculate Server.MaxHeaderBytes differently.
What does an attacker need to do to trigger the memory exhaustion?
A malicious client needs to send HTTP/2 requests containing a Trailer header that declares a large number of fields. The server creates entries in Request.Trailer for those declared fields, consuming disproportionate memory.
Do Server.MaxHeaderValueCount or Server.MaxHeaderBytes prevent this attack?
No. For HTTP/2, the declared Trailer fields can cause the allocation while bypassing both Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits.