CVE-2023-45288: Go Standard Library Net/http
High severity, CVSS 7.5. EPSS: 92% chance of exploitation in the next 30 days.
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.
Affected products
- Go Standard Library Net/http: before 1.21.9 (fixed in 1.21.9); from 1.22.0-0, before 1.22.2 (fixed in 1.22.2)
- Go Standard Library Net\/http: before 1.21.9 (fixed in 1.21.9); from 1.22.0-0, before 1.22.2 (fixed in 1.22.2)
- Golang HTTP2: before 0.23.0 (fixed in 0.23.0)
- Golang.org/x/net golang.org/x/net/http2: before 0.23.0 (fixed in 0.23.0)
Published 2024-04-04. Last modified 2026-06-17.