A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.
https://pkg.go.dev/vuln/GO-2026-6611
https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs