Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56853

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

A flaw was found in the net/http component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the ReadHeaderTimeout is not correctly applied during this process. This oversight could allow a remote attacker to maintain open connections indefinitely, potentially leading to a Denial of Service (DoS) by exhausting server resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
AWS Load Balancer Operatoralbo/aws-load-balancer-operatorAffected
AWS Load Balancer Operatoralbo/aws-load-balancer-rhel8-operatorAffected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Compliance Operatorcompliance/openshift-compliance-operator-bundleAffected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2515827net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service

EPSS

Процентиль: 45%
0.0059
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

(When a server is configured to support unencrypted HTTP/2, it reads a ...)

CVSS3: 7.5
nvd
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

CVSS3: 7.5
debian
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a ...

CVSS3: 7.5
github
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

EPSS

Процентиль: 45%
0.0059
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-56853