freenode
Languages & Toolchains

Go patches HTTP/2 CPU spike from SETTINGS window updates

CVE-2026-78669 let a malicious peer burn CPU with many streams and repeated initial window size changes.

The Go project has fixed CVE-2026-78669, a denial-of-service issue in its HTTP/2 client and server that let a malicious peer drive excessive CPU use.

An attacker could open a large number of streams and then send many small SETTINGS frames that changed SETTINGS_INITIAL_WINDOW_SIZE. Each change was processed in time proportional to the number of open streams, so the cost scaled with stream count and frame volume and could starve legitimate work on the same process.

The stack now applies initial window size updates in constant time, independent of how many streams are open, so the same traffic no longer produces that CPU spike. The flaw was reported by Jakub Ciolek. The fix is tracked as Go issue 81742.