Go HTTP/2 client fixed for Content-Length smuggling risk
CVE-2026-78660 covers a transport that forwarded conflicting length headers through reverse proxies to HTTP/1 clients.
The Go project has patched its HTTP/2 client transport over a public-track security flaw, CVE-2026-78660, in which the stack accepted multiple Content-Length headers on a single response.
HTTP/2 framing does not rely on Content-Length, so the duplicate values were easy to overlook in isolation. The risk appears when a reverse proxy built on Go’s HTTP/2 transport forwards the headers unchanged to a downstream HTTP/1 client. Clients that improperly tolerate conflicting Content-Length values can then be tricked into response smuggling; Go’s own HTTP/1 transport rejects that pattern, but third-party or legacy clients may not.
The fix stops the transport from retaining malformed framing-related headers, so conflicting length metadata is no longer passed along to HTTP/1 peers. Operators running Go-based reverse proxies or HTTP/2 clients in front of mixed HTTP/1 infrastructure should pick up the updated release once it is available.