CVE-2026-97032: HTTP/2 server crash due to HPACK encoder race in net/http
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGSHEADERTABLESIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to do to trigger the crash?
The attacker needs to interact with an HTTP/2 server and repeatedly send requests while sending SETTINGS frames that change SETTINGS_HEADER_TABLE_SIZE. The race occurs between response HEADERS encoding and processing the client-controlled header-table-size setting.
Which deployments are exposed?
Deployments using Go's net/http package as an HTTP/2 server are exposed to the described crash condition. The provided information does not identify any configuration prerequisite beyond serving HTTP/2.
What is the likely impact of successful exploitation?
Successful exploitation can crash the HTTP/2 server, resulting in denial of service. The provided information describes a concurrency race in the HPACK encoder and does not state any impact beyond server crashes.