Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56853

Опубликовано: 13 авг. 2026
Источник: debian

Описание

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.27fixed1.27~rc3-1package
golang-1.26fixed1.26.6-1package
golang-1.25fixed1.25.13-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.15removedpackage

Примечания

  • https://github.com/golang/go/issues/80205

  • Fixed by: https://github.com/golang/go/commit/cb4d292bb634ab89a62995f2384df9389d876333 (go1.27rc3)

  • Fixed by: https://github.com/golang/go/commit/5bbd22ff78daf010c5bd19c466a0c45ac78503d4 (go1.26.6)

  • Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

(When a server is configured to support unencrypted HTTP/2, it reads a ...)

CVSS3: 7.5
redhat
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

CVSS3: 7.5
nvd
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

CVSS3: 7.5
github
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.