
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-97032 is a race condition vulnerability in Go's HTTP/2 implementation that allows unauthenticated remote attackers to crash HTTP/2 servers via concurrent, unsynchronized modifications to the HPACK encoder. The flaw affects the Go standard library (net/http before 1.26.9 and net/http/internal/http2 versions 1.27.0-0 through before 1.27.2) and the external package golang.org/x/net/http2 before 0.60.0. It was disclosed on October 8, 2026, with patches released simultaneously. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is a race condition (CWE-366: Race Condition within a Thread) in the HTTP/2 HPACK encoder, which is accessed concurrently from two goroutines without proper synchronization. The first goroutine encodes HEADERS frames as part of sending responses to clients, while the second goroutine modifies the encoder's dynamic table size when processing incoming SETTINGS frames that contain SETTINGS_HEADER_TABLE_SIZE. Because no mutex or other synchronization primitive guards these concurrent accesses, a malicious client can trigger a data race by repeatedly sending HTTP/2 requests while simultaneously sending SETTINGS frames with varying header table sizes, ultimately causing the server process to crash. The issue is tracked upstream as Go issue #81867 and addressed in code changes CL/847188 and CL/847313 (Red Hat Bugzilla, Go Vuln DB).
Successful exploitation results in a denial of service (DoS) by crashing the HTTP/2 server process, causing complete loss of availability for all clients connected to that server. There is no impact on confidentiality or integrity — the vulnerability cannot be used to read or modify data. Because the crash affects the entire server process, all active HTTP/2 connections are terminated, potentially impacting downstream services that depend on the affected server (Red Hat Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code has been published, and there is no evidence of active in-the-wild exploitation as of the disclosure date. The vulnerability is exploitable by unauthenticated network attackers with no user interaction required, though the high attack complexity (requiring precise timing to trigger the race condition) limits ease of exploitation. The EPSS score is reported as 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been identified (Red Hat Advisory, Go Vuln DB).
net/http, net/http/internal/http2, or golang.org/x/net/http2 (Go < 1.26.9, Go 1.27.0–1.27.1, or x/net/http2 < 0.60.0) using banner grabbing or service fingerprinting tools.h2c tooling).SETTINGS_HEADER_TABLE_SIZE values from the same connection, exploiting the lack of synchronization between the two goroutines.SETTINGS_HEADER_TABLE_SIZE values from a single client IP, interleaved with HEADERS frames; unusual connection patterns from a single source.Upgrade to a patched Go release: Go 1.26.9 or later (for the 1.26.x branch), Go 1.27.2 or later (for the 1.27.x branch), or update the golang.org/x/net/http2 module to version 0.60.0 or later. As a temporary workaround, implement rate limiting or connection-level filtering on HTTP/2 SETTINGS frames to restrict how frequently individual clients can change the header table size. Monitor HTTP/2 server logs for unexpected crashes and restart events as an early warning signal (Red Hat Advisory, Go Vuln DB, Red Hat Bugzilla).
The vulnerability was announced via the golang-announce mailing list and tracked in the Go vulnerability database as GO-2026-6617. The Docker project released docker-v29.9.0 incorporating the fix shortly after disclosure, indicating rapid uptake in the ecosystem. Community discussion on oss-sec and social platforms (including Bluesky) noted the vulnerability's limited severity due to the high attack complexity required to reliably trigger the race condition.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."