Skip to content

net/http/internal/http2: SETTINGS_MAX_FRAME_SIZE=0 causes Transport to loop infinitely #78476

Description

@nicholashusin

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of
writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a
value of 0.

This allows potential DoS against a client by a malicious server. HTTP/2
transport now properly checks that the received SETTINGS_MAX_FRAME_SIZE is
valid.

Thanks to Marwan Atia ([email protected]) for reporting this issue.

This is CVE-2026-33814 and Go issue https://go.dev/issue/78476.


This was a PUBLIC track issue, tracked in http://b/496352405.

Activity

  1. nicholashusin commented on Mar 31, 2026

    @nicholashusin
    MemberAuthor

    @gopherbot please open backport issues for this security fix

  2. gopherbot commented on Mar 31, 2026

    @gopherbot
    Contributor

    Backport issue(s) opened: #78477 (for 1.25), #78478 (for 1.26).

    Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.

  3. gopherbot commented on Mar 31, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/761581 mentions this issue: net/http/internal/http2: prevent hanging Transport due to bad SETTINGS frame

  4. gopherbot commented on Mar 31, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/761640 mentions this issue: http2: prevent hanging Transport due to bad SETTINGS frame

  5. added a commit that references this issue on Mar 31, 2026
    e3a10fe
  6. added a commit that references this issue on Mar 31, 2026
    1e71bd8
  7. added this to the Go1.27 milestone on Apr 1, 2026
  8. added
    NeedsFixThe path to resolution is known, but the work has not been done.
    on Apr 1, 2026
  9. mrkfrmn commented on Apr 17, 2026

    @mrkfrmn
    Contributor

    It appears src/net/http/internal/http2 does not exist in go1.25 or go1.26. I assume we want to make the changes on the respective vendor branches and then bring them in for go1.25 and go1.26.

  10. nicholashusin commented on Apr 17, 2026

    @nicholashusin
    MemberAuthor

    That's correct yes. src/net/http/internal/http2 was a recent move.

    For the backport, we'd need to do cherrypick https://go.dev/cl/761640 into the vendor branches (which I think has yet to be created), and then bundle the changes into h2_bundle.go in the main repo.

  11. mrkfrmn commented on Apr 17, 2026

    @mrkfrmn
    Contributor

    Agreed, those vendor branches need to be made. Doing that now.

  12. 36 remaining items

  13. added 6 commits that reference this issue on Jun 9, 2026
    589c5f1
    fba4ac0
    5d24c34
    efe7ddf
    8e99acd
    b074eab
  14. added a commit that references this issue on Jun 17, 2026
  15. added a commit that references this issue on Jun 27, 2026
  16. added a commit that references this issue on Jul 19, 2026
  17. added 5 commits that reference this issue on Aug 17, 2026
    032d441
    7d6763b
    35dcf6b
    ecc343c
    5ea5823
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

NeedsFixThe path to resolution is known, but the work has not been done.Security

Type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions