CVE-2026-56853
published 2026-08-13CVE-2026-56853: When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
45.0th percentile
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
Affected
105 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | 3scale-operator-bundle | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| albo | aws-load-balancer-operator | — | — |
| albo | aws-load-balancer-rhel8-operator | — | — |
| ansible-automation-platform-26 | receptor-rhel9 | — | — |
| ansible-automation-platform-27 | receptor-rhel9 | — | — |
| ansible-automation-platform | platform-operator-bundle | — | — |
| apache | thrift | — | — |
| build-of-trustee | trustee-rhel9-operator | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-compliance-operator-bundle | — | — |
| compliance | openshift-selinuxd-rhel8 | — | — |
| confidential-containers | trustee | — | — |
| container-native-virtualization | kubemacpool-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | conmon | — | — |
| container-tools_rhel8 | containernetworking-plugins | — | — |
| container-tools_rhel8 | crun | — | — |
| container-tools_rhel8 | oci-seccomp-bpf-hook | — | — |
| container-tools_rhel8 | podman | — | — |
| container-tools_rhel8 | runc | — | — |
| container-tools_rhel8 | skopeo | — | — |
| container-tools_rhel8 | toolbox | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
vendor_redhat·2026-08-13·CVSS 7.5
CVE-2026-56853 [HIGH] CWE-770 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTimeout` is not correctly applied during this process. This oversight could allow a remote attacker to maintain open connections indefinitely, potentially leading to a Denial of Service (DoS) by exhausting server resources.
Package: rhai/assisted-installer-rhel9 (Assisted Installer for Red Hat OpenShift Container Platform 2) - Affected
Package: albo/aws-load-balancer-operator (AWS Load Balancer Operator) - Affected
Package: albo/aws-load-balancer-rhel8-operator
VulDB
Go nethttp up to 1.25.12/1.26.5 allocation of resources
vuldb·2026-08-14
CVE-2026-56853 [LOW] Go nethttp up to 1.25.12/1.26.5 allocation of resources
A vulnerability categorized as problematic has been discovered in Go nethttp up to 1.25.12/1.26.5. Impacted is an unknown function. The manipulation results in allocation of resources.
This vulnerability is reported as CVE-2026-56853. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface.
ghsa_unreviewed·2026-08-14
CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface.
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
No detection rules found.
No public exploits indexed.
2026-08-13
Published