Source: golang-golang-x-net
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for golang-golang-x-net.

CVE-2026-33814[0]:
| When processing HTTP/2 SETTINGS frames, transport will enter an
| infinite loop of writing CONTINUATION frames if it receives a
| SETTINGS_MAX_FRAME_SIZE with a value of 0.

https://go-review.googlesource.com/c/go/+/761581
https://go-review.googlesource.com/c/net/+/761640
https://github.com/golang/go/issues/78476


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-33814
    https://www.cve.org/CVERecord?id=CVE-2026-33814

Please adjust the affected versions in the BTS as needed.

Reply via email to