CVE-2026-78659
EUVD-2026-9541908.10.2026, 23:17
When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang-golang-x-net |
| ||||||||||||
| google-guest-agent |
| ||||||||||||
| google-osconfig-agent |
| ||||||||||||
| containerd |
| ||||||||||||
| golang-golang-x-net-dev |
| ||||||||||||
| adsys |
| ||||||||||||
| juju-core |
| ||||||||||||
| lxd |
| ||||||||||||
| golang |
| ||||||||||||
| golang-1.6 |
| ||||||||||||
| golang-1.8 |
| ||||||||||||
| golang-1.9 |
| ||||||||||||
| golang-1.10 |
| ||||||||||||
| golang-1.13 |
| ||||||||||||
| golang-1.14 |
| ||||||||||||
| golang-1.16 |
| ||||||||||||
| golang-1.17 |
| ||||||||||||
| golang-1.18 |
| ||||||||||||
| golang-1.20 |
| ||||||||||||
| golang-1.21 |
| ||||||||||||
| golang-1.22 |
| ||||||||||||
| golang-1.23 |
| ||||||||||||
| golang-1.24 |
| ||||||||||||
| golang-1.25 |
| ||||||||||||
| golang-1.26 |
| ||||||||||||
| golang-1.27 |
|
Common Weakness Enumeration
Vulnerability Media Exposure