CVE-2026-78659

high

Description

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.

References

https://pkg.go.dev/vuln/GO-2026-6603

https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs

https://groups.google.com/g/golang-announce/c/U2fTuyDJznI

https://go.dev/issue/81857

https://go.dev/cl/847314

https://go.dev/cl/847185

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95419

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-09

Named Vulnerability: GO-2026-6603

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.00227