Repository navigation
net/http/internal/http2: SETTINGS_MAX_FRAME_SIZE=0 causes Transport to loop infinitely #78476
Description
Activity
@gopherbot please open backport issues for this security fix
Backport issue(s) opened: #78477 (for 1.25), #78478 (for 1.26).
Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.
Change https://go.dev/cl/761581 mentions this issue:
net/http/internal/http2: prevent hanging Transport due to bad SETTINGS frameChange https://go.dev/cl/761640 mentions this issue:
http2: prevent hanging Transport due to bad SETTINGS frame- added a commit that references this issue
on Mar 31, 2026 - added a commit that references this issue
on Mar 31, 2026 - addedNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.
on Apr 1, 2026 It appears src/net/http/internal/http2 does not exist in go1.25 or go1.26. I assume we want to make the changes on the respective vendor branches and then bring them in for go1.25 and go1.26.
That's correct yes.
src/net/http/internal/http2was a recent move.For the backport, we'd need to do cherrypick https://go.dev/cl/761640 into the vendor branches (which I think has yet to be created), and then bundle the changes into
h2_bundle.goin the main repo.Agreed, those vendor branches need to be made. Doing that now.
Reacted by Nicholas S. Husin36 remaining items
- added 6 commits that reference this issue
on Jun 9, 2026 - added a commit that references this issue
on Jun 17, 2026 - added a commit that references this issue
on Jun 23, 2026 - added a commit that references this issue
on Jun 27, 2026 - added a commit that references this issue
on Jul 19, 2026 - added 5 commits that reference this issue
on Aug 17, 2026
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of
writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a
value of 0.
This allows potential DoS against a client by a malicious server. HTTP/2
transport now properly checks that the received SETTINGS_MAX_FRAME_SIZE is
valid.
Thanks to Marwan Atia ([email protected]) for reporting this issue.
This is CVE-2026-33814 and Go issue https://go.dev/issue/78476.
This was a PUBLIC track issue, tracked in http://b/496352405.