CVE-2026-78669: Go Standard Library Net/http

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.

Affected products

Published 2026-10-08. Last modified 2026-10-09.