---
id: CVE-2026-78659
title: >-
  When "Trailer" headers are sent by a client, the HTTP server internally uses
  the header values to populate the Request.Trailer map passed to the server
  handler
summary: >-
  When "Trailer" headers are sent by a client, the HTTP server internally uses
  the header values to populate the Request.Trailer map passed to the server
  handler. Because Request.Trailer is a map, each entry incurs memory overhead.
  For HTT…
severity: none
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:17:03.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78659'
references:
  - url: 'https://go.dev/cl/847185'
    label: security@golang.org
  - url: 'https://go.dev/cl/847314'
    label: security@golang.org
  - url: 'https://go.dev/issue/81857'
    label: security@golang.org
  - url: 'https://groups.google.com/g/golang-announce/c/U2fTuyDJznI'
    label: security@golang.org
  - url: 'https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs'
    label: security@golang.org
  - url: 'https://pkg.go.dev/vuln/GO-2026-6603'
    label: security@golang.org
tags:
  - nvd
ingestedAt: '2026-10-09T00:19:50.975Z'
---

## Overview

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
