Description
The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Published:
2026-10-08
Score:
n/a
EPSS:
n/a
KEV:
No
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control. | |
| Title | Double flow control refund on HTTP/2 server streams in net/http | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-10-08T22:53:59.772Z
Reserved: 2026-08-24T23:36:15.738Z
Link: CVE-2026-78663
No data.
Status : Received
Published: 2026-10-08T23:17:03.647
Modified: 2026-10-08T23:17:03.647
Link: CVE-2026-78663
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.