Description
The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Fri, 09 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library net/http
Go Standard Library net/http2
Vendors & Products Go Standard Library
Go Standard Library net/http
Go Standard Library net/http2

Fri, 09 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Title Double flow control refund on HTTP/2 server streams in net/http
References

Subscriptions

Go Standard Library Net/http Net/http2
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-09T16:42:50.839Z

Reserved: 2026-08-24T23:36:15.738Z

Link: CVE-2026-78663

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T23:17:03.647

Modified: 2026-10-09T16:35:35.900

Link: CVE-2026-78663

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-08T22:53:59Z

Links: CVE-2026-78663 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T14:45:07Z

Weaknesses