Skip to main content

Vendor/product archive

golang / http2 CVEs

Beta · best-effort

5 CVEs tagged to golang / http20 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-33814

Published May 7, 2026

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

CVSS 7.5 · High
evidence mentions
19
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2022-41723

Published Feb 28, 2023

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1