Fwd: Vulnerabilities in golang.org/x/net
Go released golang.org/x/net v0.60.0 to fix HTTP/2 server memory exhaustion caused by Trailer headers.
The Go project tagged golang.org/x/net v0.60.0 to address security issues, according to a notice forwarded to oss-security. One issue is HTTP/2 server memory exhaustion triggered by Trailer headers. The announcement does not list a CVE or say the flaw is being exploited.
- golang.org/x/net v0.60.0 was tagged to fix security issues.
- HTTP/2 servers can exhaust memory when clients send Trailer headers.
- The notice was forwarded to oss-security and reports no exploitation.
Posted by Alan Coopersmith on Oct 08 -------- Forwarded Message -------- Subject: [security] Vulnerabilities in golang.org/x/net Date: Thu, 8 Oct 2026 18:09:23 +0000 From: announce () golang org To: golang-nuts () googlegroups com Hello gophers, We have tagged version v0.60.0 of golang.org/x/net in order to address the following security issues: * net/http: HTTP/2 server memory exhaustion due to Trailer headers When "Trailer" headers are sent by...
This source does not provide full text. Read it at seclists.org.