---
id: CVE-2026-56853
title: >-
  net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to
  Denial of Service (CVE-2026-56853)
summary: >-
  A flaw was found in the `net/http` component of the Go standard library. When
  a server is configured to support unencrypted HTTP/2, it reads initial bytes
  from new connections to detect the HTTP/2 client preface. However, the
  `ReadHeaderTi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4.22
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - aws_load_balancer_operator
  - cert_manager_operator_for_red_hat_openshift
  - compliance_operator
  - confidential_compute_attestation
  - deployment_validation_operator
  - exploit_intelligence
  - externaldns_operator
  - fence_agents_remediation_operator
  - file_integrity_operator
  - logging_subsystem_for_red_hat_openshift
  - logical_volume_manager_storage
  - machine_deletion_remediation_operator
  - migration_toolkit_for_applications 8
  - multicluster_engine_for_kubernetes
  - node_healthcheck_operator
  - node_maintenance_operator
  - openshift_developer_tools_and_services
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_serverless
  - power_monitoring_for_red_hat_openshift
  - 3scale_api_management_platform 2
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - ai_inference_server
  - ansible_automation_platform 2
  - ceph_storage 5
  - ceph_storage 6
  - ceph_storage 7
  - ceph_storage 8
  - ceph_storage 9
  - certification_program_for_red_hat_enterprise_linux 9
  - connectivity_link 1
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - lightspeed_for_runtimes_operator
  - openshift_ai_rhoai
patched:
  - ansible_automation_platform_2_6_for_rhel 10
  - ansible_automation_platform_2_7_for_rhel 10
  - rhem_1_1_for_rhel 10
  - rhem_1_2_for_rhel 10
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - ansible_automation_platform_2_7_for_rhel 9
  - rhem_1_1_for_rhel 9
  - rhem_1_2_for_rhel 9
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_v_10
  - custom_metric_autoscaler 2.19
  - logging_subsystem_for_red_hat_openshift 6.2
  - logging_subsystem_for_red_hat_openshift 6.5
  - logging_subsystem_for_red_hat_openshift 6.6
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.5.8
  - multicluster_global_hub 1.7.3
  - multicluster_global_hub 1.8.2
  - network_observability_netobserv 1.12.3
  - openshift_api_for_data_protection 1.5
  - openshift_compliance_operator 1
  - openshift_developer_tools_and_services 1.6.4
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.6
  - developer_hub 1.9
  - edge_manager 1.1
  - edge_manager 1.2
published: '2026-08-13'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:20:02+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56853.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56853.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-56853'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515827'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-56853'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56853'
  - url: 'https://go.dev/cl/795540'
  - url: 'https://go.dev/issue/80205'
  - url: 'https://groups.google.com/g/golang-announce/c/94pEornpRlI'
  - url: 'https://pkg.go.dev/vuln/GO-2026-6089'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71113'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71112'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68334'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68335'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71114'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65918'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61882'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67517'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66459'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65335'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67974'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66327'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70103'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63332'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64777'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62578'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60306'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63022'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63119'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65534'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62631'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65116'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65895'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70201'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64818'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63163'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60305'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62407'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63124'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66016'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64786'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62602'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65359'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62754'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62405'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00568
epssPercentile: 0.44648
aliases:
  - GO-2026-6089
  - BIT-golang-2026-56853
ecosystem: go
ingestedAt: '2026-08-14T19:18:46.559Z'
---

## Overview

A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTimeout` is not correctly applied during this process. This oversight could allow a remote attacker to maintain open connections indefinitely, potentially leading to a Denial of Service (DoS) by exhausting server resources.

## Vendor advisories

- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)
- **RHSA-2026:71112** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 for RHEL 10, Red Hat Ansible Automation Platform 2.7 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71112)
- **RHSA-2026:68334** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68334)
- **RHSA-2026:68335** · Red Hat · fixed in: RHEM 1.2 for RHEL 10, RHEM 1.2 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68335)
- **RHSA-2026:71114** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71114)
- **RHSA-2026:65918** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:65918)
- **RHSA-2026:61882** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:61882)
- **RHSA-2026:67517** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67517)
- **RHSA-2026:66459** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66459)
- **RHSA-2026:65335** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65335)
- **RHSA-2026:67974** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67974)
- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, AWS Load Balancer Operator, cert-manager Operator for Red Hat OpenShift, Compliance Operator, Confidential Compute Attestation, Deployment Validation Operator, … · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56853.json)
- **RHSA-2026:66327** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66327)
- **RHSA-2026:70103** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70103)
- **RHSA-2026:63332** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:63332)
- **RHSA-2026:64777** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64777)
- **RHSA-2026:62578** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62578)
- **RHSA-2026:60306** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60306)
- **RHSA-2026:63022** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63022)
- **RHSA-2026:63119** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63119)
- **RHSA-2026:65534** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65534)
- **RHSA-2026:62631** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62631)
- **RHSA-2026:65116** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65116)

**net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-24.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- AWS Load Balancer Operator
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Deployment Validation Operator
- Exploit Intelligence
- ExternalDNS Operator
- Fence Agents Remediation Operator
- File Integrity Operator
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Applications 8
- Multicluster Engine for Kubernetes
- Node HealthCheck Operator
- Node Maintenance Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Certification Program for Red Hat Enterprise Linux 9
- Red Hat Connectivity Link 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Lightspeed for Runtimes Operator
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.7 for RHEL 10
- RHEM 1.1 for RHEL 10
- RHEM 1.2 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Ansible Automation Platform 2.7 for RHEL 9
- RHEM 1.1 for RHEL 9
- RHEM 1.2 for RHEL 9
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- Custom Metric Autoscaler 2.19
- Logging Subsystem for Red Hat OpenShift 6.2
- Logging Subsystem for Red Hat OpenShift 6.5
- Logging Subsystem for Red Hat OpenShift 6.6
- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.5.8
- Multicluster Global Hub 1.7.3
- Multicluster Global Hub 1.8.2
- Network Observability (NETOBSERV) 1.12.3
- OpenShift API for Data Protection 1.5
- OpenShift Compliance Operator 1
- OpenShift Developer Tools and Services 1.6.4
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.6
- Red Hat Developer Hub 1.9
- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2

No fix planned:

- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4
- Secrets Management Console for Red Hat OpenShift
- Zero Trust Workload Identity Manager - Tech Preview
- Assisted Installer for Red Hat OpenShift Container Platform 2
- AWS Load Balancer Operator
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Deployment Validation Operator
- Exploit Intelligence
- ExternalDNS Operator
- Fence Agents Remediation Operator
- File Integrity Operator
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Applications 8
- Multicluster Engine for Kubernetes
- Node HealthCheck Operator
- Node Maintenance Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Certification Program for Red Hat Enterprise Linux 9
- Red Hat Connectivity Link 1
- Red Hat Enterprise Linux 8

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.7 for RHEL 10
- RHEM 1.1 for RHEL 10
- RHEM 1.2 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Ansible Automation Platform 2.7 for RHEL 9
- RHEM 1.1 for RHEL 9
- RHEM 1.2 for RHEL 9

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:71113
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:71112
See the following documentation for details on how to enable Red Hat Edge
Manager and more:
https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68334

## Package advisory (CVE-2026-56853)

Affected packages:

- `stdlib >= 1.27.0-0, < 1.27.0-rc.3`

Patched in:

- `stdlib 1.27.0-rc.3`

Source: https://osv.dev/vulnerability/GO-2026-6089
