Go x/net 0.60.0 patches HTTP/2 memory and CPU exhaustion flaws
Three server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.
By segfaultThree server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.
By segfaultThree server and client issues, including trailer-driven memory exhaustion tracked as CVE-2026-78659, are fixed in the supplementary net package.
By segfault