CVE-2026-56853: CWE-770: Allocation of Resources Without Limits or Throttling in Go standard library net/http
CVE-2026-56853 is a high-severity vulnerability in the Go standard library net/http package. It occurs when a server supports unencrypted HTTP/2 and reads initial bytes from new connections to detect the HTTP/2 client preface. During this process, the ReadHeaderTimeout setting is not applied as expected, leading to allocation of resources without proper limits or throttling. This can cause denial of service by exhausting server resources.
AI Analysis
Technical Summary
This vulnerability (CWE-770) in the Go standard library's net/http package arises because when unencrypted HTTP/2 is enabled, the server reads a few bytes from each new connection to check for the HTTP/2 client preface. However, the ReadHeaderTimeout is not enforced during this read operation, allowing an attacker to open many connections that consume server resources without timeout enforcement. This lack of throttling can lead to resource exhaustion and denial of service conditions.
Potential Impact
The vulnerability can be exploited to cause denial of service by exhausting server resources, as the server does not apply the expected ReadHeaderTimeout when reading the HTTP/2 client preface bytes. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been documented.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling unencrypted HTTP/2 support or implementing external connection rate limiting to mitigate resource exhaustion risks.
CVE-2026-56853: CWE-770: Allocation of Resources Without Limits or Throttling in Go standard library net/http
Description
CVE-2026-56853 is a high-severity vulnerability in the Go standard library net/http package. It occurs when a server supports unencrypted HTTP/2 and reads initial bytes from new connections to detect the HTTP/2 client preface. During this process, the ReadHeaderTimeout setting is not applied as expected, leading to allocation of resources without proper limits or throttling. This can cause denial of service by exhausting server resources.
CVSS v3.1
Score 7.5high
Affected software
Go standard library
net/http
pkg:golang/net/httpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-770) in the Go standard library's net/http package arises because when unencrypted HTTP/2 is enabled, the server reads a few bytes from each new connection to check for the HTTP/2 client preface. However, the ReadHeaderTimeout is not enforced during this read operation, allowing an attacker to open many connections that consume server resources without timeout enforcement. This lack of throttling can lead to resource exhaustion and denial of service conditions.
Potential Impact
The vulnerability can be exploited to cause denial of service by exhausting server resources, as the server does not apply the expected ReadHeaderTimeout when reading the HTTP/2 client preface bytes. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been documented.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling unencrypted HTTP/2 support or implementing external connection rate limiting to mitigate resource exhaustion risks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-06-23T15:10:49.352Z
- State
- PUBLISHED
Threat ID: 6a7e412ebf8831d539e05119
Added to database: 08/13/2026, 22:11:58 UTC
Last enriched: 08/21/2026, 14:01:55 UTC
Last updated: 09/28/2026, 19:45:19 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.