CVE-2026-78669: Excessive CPU consumption from repeated initial window changes in net/http
Published Oct 8, 2026
·Updated
A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGSINITIALWINDOWSIZE values.
Affected Software
1 affected component
go Go net/http
Event History
Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Go applications are exposed to this issue?
Go applications using net/http as an HTTP/2 client or server can be exposed when communicating with a malicious HTTP/2 peer.
2
What does an attacker need to do to trigger the CPU consumption?
The attacker needs to act as an HTTP/2 peer, open a large number of streams, and send many small SETTINGS frames that contain SETTINGS_INITIAL_WINDOW_SIZE values.
3
What is the practical impact of exploitation?
Exploitation can cause excessive CPU consumption in the affected net/http HTTP/2 client or server.