---
id: CVE-2026-78663
title: >-
  The HTTP/2 server can refund connection-level flow control twice for the same
  data: Once when a client resets a stream (refunding data for any
  sent-but-unread portion of the stream), and again when a request handler reads
  the buffered da…
summary: >-
  The HTTP/2 server can refund connection-level flow control twice for the same
  data: Once when a client resets a stream (refunding data for any
  sent-but-unread portion of the stream), and again when a request handler reads
  the buffered da…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-675
  - CWE-770
vendor: stdlib
product: stdlib
affected:
  - stdlib < 1.26.9
  - 'stdlib >= 1.27.0-0, < 1.27.2'
  - golang.org/x/net < 0.60.0
patched:
  - stdlib 1.26.9
  - stdlib 1.27.2
  - golang.org/x/net 0.60.0
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:16:49.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78663'
references:
  - url: 'https://go.dev/cl/847187'
    label: security@golang.org
  - url: 'https://go.dev/cl/847310'
    label: security@golang.org
  - url: 'https://go.dev/issue/81743'
    label: security@golang.org
  - url: 'https://groups.google.com/g/golang-announce/c/U2fTuyDJznI'
    label: security@golang.org
  - url: 'https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs'
    label: security@golang.org
  - url: 'https://pkg.go.dev/vuln/GO-2026-6612'
    label: security@golang.org
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78663.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-78663'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2548345'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-78663'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78663'
tags:
  - nvd
  - osv
  - go
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.00248
epssPercentile: 0.14768
aliases:
  - GO-2026-6612
ecosystem: go
scores:
  nvd: 9.1
  vendor: 5.3
ingestedAt: '2026-10-09T00:19:50.975Z'
---

## Overview

The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-78663)

Affected packages:

- `stdlib < 1.26.9`
- `stdlib >= 1.27.0-0, < 1.27.2`
- `golang.org/x/net < 0.60.0`

Patched in:

- `stdlib 1.26.9`
- `stdlib 1.27.2`
- `golang.org/x/net 0.60.0`

Source: https://osv.dev/vulnerability/GO-2026-6612

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: OpenShift Developer Tools and Services, OpenShift Pipelines, OpenShift Serverless, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Ceph Storage 7, … · no fix planned: OpenShift Developer Tools and Services, Red Hat Ansible Automation Platform 2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-10-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78663.json)
