Fwd: Vulnerabilities in golang.org/x/net
Go released golang.org/x/net v0.60.0 to fix HTTP/2 server memory exhaustion caused by Trailer headers.
The Go project tagged golang.org/x/net v0.60.0 to address security issues, according to a notice forwarded to oss-security. One issue is HTTP/2 server memory exhaustion triggered by Trailer headers. The announcement does not list a CVE or say the flaw is being exploited.