The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-399 |
Thu, 08 Oct 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control. | |
| Title | Double flow control refund on HTTP/2 server streams in net/http | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-10-08T22:53:59.772Z
Reserved: 2026-08-24T23:36:15.738Z
Link: CVE-2026-78663
No data.
Status : Received
Published: 2026-10-08T23:17:03.647
Modified: 2026-10-08T23:17:03.647
Link: CVE-2026-78663
No data.
OpenCVE Enrichment
Updated: 2026-10-09T01:30:18Z
Weaknesses