CVE-2026-97032
Public on 2026-10-08
Modified on 2026-10-10
Description
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Fix this issue by not applying SETTINGS_HEADER_TABLE_SIZE immediately.Instead, buffer any SETTINGS_HEADER_TABLE_SIZE received, and only apply the new value prior to the next time the server writes a frame.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81867
NOTE: Fixed by: https://github.com/golang/go/commit/12acaf3086437e140e2dd3b7d2c30fdd633c5fe0 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/6e049521882c944afc1e519a83971ec421dc2974 (go1.26.9)
Fix this issue by not applying SETTINGS_HEADER_TABLE_SIZE immediately.Instead, buffer any SETTINGS_HEADER_TABLE_SIZE received, and only apply the new value prior to the next time the server writes a frame.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81867
NOTE: Fixed by: https://github.com/golang/go/commit/12acaf3086437e140e2dd3b7d2c30fdd633c5fe0 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/6e049521882c944afc1e519a83971ec421dc2974 (go1.26.9)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | golang | Pending Fix | ||
| Amazon Linux 2023 | golang | Pending Fix | ||
| Amazon Linux 2027 Preview | golang | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |