The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.
Title Double flow control refund on HTTP/2 server streams in net/http
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:59.772Z

Reserved: 2026-08-24T23:36:15.738Z

Link: CVE-2026-78663

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:03.647

Modified: 2026-10-08T23:17:03.647

Link: CVE-2026-78663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:30:18Z

Weaknesses