CVE-2026-78660: HTTP/2 transport accepts malformed framing-related headers in net/http
Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.
Affected Software
Event History
Frequently Asked Questions
What deployment pattern is required for exploitation?
The affected Go HTTP/2 implementation must be acting as a reverse proxy and forwarding a response containing malformed framing-related headers to an HTTP/1 client. Exploitation additionally depends on that HTTP/1 client not handling those headers strictly enough.
Which systems are most exposed?
Systems that proxy HTTP/2 responses through Go's net/http implementation to HTTP/1 clients are the relevant exposure path. Deployments that do not perform this HTTP/2-to-HTTP/1 reverse-proxy forwarding are not described as susceptible to the response-smuggling scenario.