CVE-2026-78667: Go Standard Library Net/http
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.
Affected products
- Go Standard Library Net/http: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)
Published 2026-10-08. Last modified 2026-10-09.