CVE-2026-78663: Double flow control refund on HTTP/2 server streams in net/http
The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
HTTP/2 servers using Go's net/http are exposed if they accept malicious client connections. The issue concerns the configured connection-level receive buffer limit, MaxReceiveBufferPerConnection.
What does an attacker need to do to exploit it?
An attacker needs to send data on an HTTP/2 stream, reset that stream, and have the request handler read the buffered data. This causes the same sent-but-unread data to be refunded twice at the connection level.
Does this allow unlimited server-side buffering?
No. Although the attacker can bypass the connection-level flow-control limit, total buffered data remains constrained by the concurrent stream limit and stream-level flow control.