CVE-2026-78667: Go Standard Library Net/http

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.

Affected products

  • Go Standard Library Net/http: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)

Published 2026-10-08. Last modified 2026-10-09.