CVE-2026-97032

Public on 2026-10-08
Modified on 2026-10-10
Description
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.

Fix this issue by not applying SETTINGS_HEADER_TABLE_SIZE immediately.Instead, buffer any SETTINGS_HEADER_TABLE_SIZE received, and only apply the new value prior to the next time the server writes a frame.

NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81867
NOTE: Fixed by: https://github.com/golang/go/commit/12acaf3086437e140e2dd3b7d2c30fdd633c5fe0 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/6e049521882c944afc1e519a83971ec421dc2974 (go1.26.9)
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core golang Pending Fix
Amazon Linux 2023 golang Pending Fix
Amazon Linux 2027 Preview golang Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H