CVE-2026-78667: Lack of limit on size of parsed Range headers in net/http
Published Oct 8, 2026
·Updated
When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.
Affected Software
1 affected component
go net/http
Event History
Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness