CVE-2026-97032: 
cAdvisor vulnerability analysis and mitigation

Overview

CVE-2026-97032 is a race condition vulnerability in Go's HTTP/2 implementation that allows unauthenticated remote attackers to crash HTTP/2 servers via concurrent, unsynchronized modifications to the HPACK encoder. The flaw affects the Go standard library (net/http before 1.26.9 and net/http/internal/http2 versions 1.27.0-0 through before 1.27.2) and the external package golang.org/x/net/http2 before 0.60.0. It was disclosed on October 8, 2026, with patches released simultaneously. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is a race condition (CWE-366: Race Condition within a Thread) in the HTTP/2 HPACK encoder, which is accessed concurrently from two goroutines without proper synchronization. The first goroutine encodes HEADERS frames as part of sending responses to clients, while the second goroutine modifies the encoder's dynamic table size when processing incoming SETTINGS frames that contain SETTINGS_HEADER_TABLE_SIZE. Because no mutex or other synchronization primitive guards these concurrent accesses, a malicious client can trigger a data race by repeatedly sending HTTP/2 requests while simultaneously sending SETTINGS frames with varying header table sizes, ultimately causing the server process to crash. The issue is tracked upstream as Go issue #81867 and addressed in code changes CL/847188 and CL/847313 (Red Hat Bugzilla, Go Vuln DB).

Impact

Successful exploitation results in a denial of service (DoS) by crashing the HTTP/2 server process, causing complete loss of availability for all clients connected to that server. There is no impact on confidentiality or integrity — the vulnerability cannot be used to read or modify data. Because the crash affects the entire server process, all active HTTP/2 connections are terminated, potentially impacting downstream services that depend on the affected server (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been published, and there is no evidence of active in-the-wild exploitation as of the disclosure date. The vulnerability is exploitable by unauthenticated network attackers with no user interaction required, though the high attack complexity (requiring precise timing to trigger the race condition) limits ease of exploitation. The EPSS score is reported as 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been identified (Red Hat Advisory, Go Vuln DB).

Exploitation steps

  1. Identify target: Locate HTTP/2 servers built with a vulnerable version of Go's net/http, net/http/internal/http2, or golang.org/x/net/http2 (Go < 1.26.9, Go 1.27.0–1.27.1, or x/net/http2 < 0.60.0) using banner grabbing or service fingerprinting tools.
  2. Establish HTTP/2 connection: Open an HTTP/2 connection to the target server using a tool or custom client that supports raw HTTP/2 frame manipulation (e.g., a custom Go client or h2c tooling).
  3. Send concurrent requests and SETTINGS frames: Simultaneously send HTTP/2 HEADERS frames (triggering response encoding) and SETTINGS frames with varying SETTINGS_HEADER_TABLE_SIZE values from the same connection, exploiting the lack of synchronization between the two goroutines.
  4. Trigger race condition: Repeat the concurrent request/SETTINGS pattern at high frequency to maximize the probability of hitting the unsynchronized concurrent access window in the HPACK encoder.
  5. Achieve DoS: The race condition causes a crash in the server process, resulting in denial of service for all connected clients (Red Hat Bugzilla, Go Vuln DB).

Indicators of compromise

  • Logs: Sudden HTTP/2 server process crashes or panics in application logs, particularly Go runtime panic messages referencing concurrent map writes or memory corruption in HPACK-related code paths.
  • Network: High-frequency HTTP/2 SETTINGS frames with rapidly changing SETTINGS_HEADER_TABLE_SIZE values from a single client IP, interleaved with HEADERS frames; unusual connection patterns from a single source.
  • Process: Unexpected termination or restart of Go-based HTTP/2 server processes; process crash dumps or core files generated by the Go runtime.
  • Availability: Repeated, unexplained service outages or restarts of HTTP/2-based services correlating with traffic from specific client IPs (Red Hat Bugzilla).

Mitigation and workarounds

Upgrade to a patched Go release: Go 1.26.9 or later (for the 1.26.x branch), Go 1.27.2 or later (for the 1.27.x branch), or update the golang.org/x/net/http2 module to version 0.60.0 or later. As a temporary workaround, implement rate limiting or connection-level filtering on HTTP/2 SETTINGS frames to restrict how frequently individual clients can change the header table size. Monitor HTTP/2 server logs for unexpected crashes and restart events as an early warning signal (Red Hat Advisory, Go Vuln DB, Red Hat Bugzilla).

Community reactions

The vulnerability was announced via the golang-announce mailing list and tracked in the Go vulnerability database as GO-2026-6617. The Docker project released docker-v29.9.0 incorporating the fix shortly after disclosure, indicating rapid uptake in the ecosystem. Community discussion on oss-sec and social platforms (including Bluesky) noted the vulnerability's limited severity due to the high attack complexity required to reliably trigger the race condition.

Additional resources


Source: This report was generated using AI

Related cAdvisor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97031HIGH7.5
  • cAdvisor logocAdvisor
  • prometheus-statsd-exporter-fips-0.22
NoYesOct 08, 2026
CVE-2026-94440HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-elasticache-fips
NoYesOct 08, 2026
CVE-2026-94448MEDIUM6.1
  • cAdvisor logocAdvisor
  • longhorn-share-manager-fips-1.9
NoYesOct 08, 2026
CVE-2026-97032MEDIUM5.9
  • cAdvisor logocAdvisor
  • task
NoYesOct 08, 2026
CVE-2026-97030NONEN/A
  • cAdvisor logocAdvisor
  • cluster-api-1.14
NoYesOct 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management