SecurityProgramming Languages

Go 1.27.2: 15 CVEs, Two HTTP/2 Crash Vectors — Patch Now

Go gopher with security shield icons representing CVE patches in Go 1.27.2
Go 1.27.2 patches 15 CVEs including HTTP/2 server crash vulnerabilities

Go 1.27.2 and its 1.26 counterpart, Go 1.26.9, landed on October 8 with fixes for 15 security vulnerabilities — the most CVEs in a single Go patch release in recent memory. Seven of those live in net/http. If you’re running an HTTP/2 server written in Go and haven’t updated, you have at least two remotely exploitable crash vectors sitting open right now.

The Crash: CVE-2026-97032, HPACK Encoder Race

The most critical fix is a denial-of-service in Go’s HTTP/2 server. The server’s HPACK header compression encoder can be modified concurrently by two goroutines without synchronization. A malicious client exploits this by sending repeated requests while simultaneously changing the SETTINGS_HEADER_TABLE_SIZE compression setting on the same connection. The result is a race condition that crashes the server process.

No authentication required. No special privileges needed. Any publicly reachable HTTP/2 endpoint running a vulnerable Go version is exposed. The fix buffers the setting change and applies it only before the next frame write, eliminating the race. This one is classified HIGH. Update immediately.

The Smuggling Pair: CVE-2026-56866 and CVE-2026-94439

Two separate CONNECT-related request smuggling vulnerabilities were patched — one on the client side, one on the server side. Both matter most to Go services acting as reverse proxies, which is a large slice of production Go deployments.

CVE-2026-56866 (client): When http.Transport sends a CONNECT request with a non-empty Request.Body, those body bytes get written directly onto the wire immediately after the request headers. Since CONNECT requests aren’t supposed to have a body, the proxy server typically rejects the request — but if the rejection includes a Keep-Alive header and no response body, Go’s transport happily returns the connection to its idle pool. The body bytes, now orphaned on the wire, get interpreted as a new HTTP request by the next caller that reuses that connection. The fix closes connections after any CONNECT exchange, regardless of the response.

CVE-2026-94439 (server): On the server side, if a handler returns after sending a 2xx CONNECT response, the tunneled data streaming through the connection can be interpreted as new HTTP requests by intermediate proxies. This is a classic HTTP request smuggling scenario. The fix always closes the connection after a CONNECT response.

Memory Exhaustion: CVE-2026-78659 and CVE-2026-78667

Two more net/http vulnerabilities target memory and CPU through legitimate-looking requests.

CVE-2026-78659 abuses the HTTP/2 “Trailer” header. A client can send a Trailer header declaring an arbitrarily large number of fields. The server allocates a map entry for each one. The problem: Server.MaxHeaderValueCount and Server.MaxHeaderBytes don’t apply to trailer field declarations — only to sent headers. HTTP/2’s multiplexing makes this especially cheap to sustain; the attacker never needs to reconnect. The fix applies limits to declared trailer fields just as they apply to regular headers.

CVE-2026-78667 hits file-serving endpoints. Any endpoint using FileServer, ServeContent, or ServeFile burns CPU parsing every range in a client-supplied Range header. Send a header with 500 ranges and the server does 500 units of work. The patch ignores Range headers with more than 200 entries. If legitimate clients need higher limits, set GODEBUG=httpservecontentmaxranges=N.

Who Is Actually Affected

If your app does thisCVEs that apply
Runs HTTP/2 server (stdlib)CVE-2026-97032, 78659, 78663, 78667, 78669
Reverse proxy / uses ReverseProxyCVE-2026-56866, 94439, 78660
TLS with Encrypted Client HelloCVE-2026-97031
html/template with inline JSCVE-2026-94448, 97030
Multipart form parsingCVE-2026-94440
Windows + os.Root.MkdirCVE-2026-56857

How to Update

# Update toolchain to 1.27.2
go get go@1.27.2

# Verify
go version
# Expected: go version go1.27.2 linux/amd64

# If you use golang.org/x/net directly, also update:
go get golang.org/x/net@v0.60.0

Binary installs: download directly from go.dev/dl. Still on Go 1.26? Grab 1.26.9 — the same 15 CVEs are backported there.

The Rest of the Patch

Beyond net/http, five more areas in this release are worth a quick note:

  • crypto/tls (CVE-2026-97031): Multiple ECH outer extension references trigger memory exhaustion on TLS servers accepting Encrypted Client Hello. The fix rejects malformed references per RFC 9849.
  • html/template (CVE-2026-94448, 97030): JavaScript template literals with consecutive expressions break context tracking. Subsequent regex literals and the yield keyword escape incorrectly — a potential XSS path in server-rendered templates.
  • mime/multipart (CVE-2026-94440): Memory limit enforcement fails when the remaining allowed limit drops below 400 bytes during multipart form parsing. Arbitrary lines get read into memory unchecked.
  • os/Windows (CVE-2026-56857): Root.Mkdir(All) follows junctions outside the root directory. Windows-only, but relevant for any Go code doing containerized filesystem operations.
  • cmd/go (CVE-2026-94444, 94447): Two checksum verification bypasses for FIPS and toolchain module downloads. Relevant to projects with strict supply chain controls.

Why 15 CVEs at Once?

HTTP/2 is complex. HPACK compression, flow control accounting, CONNECT semantics, window size updates — each a separate protocol subsystem, each a place where subtle implementation errors open up DoS or smuggling paths. Go’s stdlib HTTP/2 implementation is used at enormous scale — Kubernetes, Docker, cloud tooling — which means it gets more scrutiny. That’s a good thing. Fifteen CVEs in one release isn’t a sign that Go is suddenly insecure; it’s a sign the security research community is doing its job.

That said: patch now. The official announcement is up, the fix is straightforward, and the HPACK crash (CVE-2026-97032) is simple enough to trigger that waiting is not a reasonable posture. Check whether you also use golang.org/x/net/http2 directly — if so, v0.60.0 patches those separately from the stdlib update.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:Security