CVE-2026-78659

Public on 2026-10-08
Modified on 2026-10-10
Description
When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits.
This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.
Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits are now applied towards the trailer fields declared in "Trailer" headers.

NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81857
NOTE: Fixed by: https://github.com/golang/go/commit/cbb0fb8b51cba866018b8a0fb4b5458f16c5c80b (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/6e049521882c944afc1e519a83971ec421dc2974 (go1.26.9)
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core amazon-cloudwatch-agent Pending Fix
Amazon Linux 2023 amazon-cloudwatch-agent Pending Fix
Amazon Linux 2027 Preview amazon-cloudwatch-agent Pending Fix
Amazon Linux 2 - Docker Extra amazon-ecr-credential-helper Pending Fix
Amazon Linux 2023 amazon-ecr-credential-helper Pending Fix
Amazon Linux 2027 Preview amazon-ecr-credential-helper Pending Fix
Amazon Linux 2 - Core amazon-ssm-agent Pending Fix
Amazon Linux 2023 amazon-ssm-agent Pending Fix
Amazon Linux 2027 Preview amazon-ssm-agent Pending Fix
Amazon Linux 2023 buildah Pending Fix
Amazon Linux 2027 Preview buildah Pending Fix
Amazon Linux 2 - Core cni-plugins Pending Fix
Amazon Linux 2023 cni-plugins Pending Fix
Amazon Linux 2027 Preview cni-plugins Pending Fix
Amazon Linux 2 - Docker Extra containerd Pending Fix
Amazon Linux 2023 containerd Pending Fix
Amazon Linux 2027 Preview containerd Pending Fix
Amazon Linux 2023 credentials-fetcher Pending Fix
Amazon Linux 2027 Preview credentials-fetcher Pending Fix
Amazon Linux 2 - Core cri-tools Pending Fix
Amazon Linux 2 - Docker Extra docker Pending Fix
Amazon Linux 2023 docker Pending Fix
Amazon Linux 2027 Preview docker Pending Fix
Amazon Linux 2 - Ecs Extra ecs-init Pending Fix
Amazon Linux 2023 ecs-init Pending Fix
Amazon Linux 2027 Preview ecs-init Pending Fix
Amazon Linux 2023 git-lfs Pending Fix
Amazon Linux 2027 Preview git-lfs Pending Fix
Amazon Linux 2 - Core golang Pending Fix
Amazon Linux 2 - Golang1.11 Extra golang No Fix Planned
Amazon Linux 2 - Golang1.19 Extra golang No Fix Planned
Amazon Linux 2 - Golang1.9 Extra golang No Fix Planned
Amazon Linux 2023 golang Pending Fix
Amazon Linux 2027 Preview golang Pending Fix
Amazon Linux 2023 libcap Pending Fix
Amazon Linux 2027 Preview libcap Pending Fix
Amazon Linux 2 - Core nerdctl Pending Fix
Amazon Linux 2023 nerdctl Pending Fix
Amazon Linux 2027 Preview nerdctl Pending Fix
Amazon Linux 2 - Docker Extra oci-add-hooks Pending Fix
Amazon Linux 2023 oci-add-hooks Pending Fix
Amazon Linux 2027 Preview oci-add-hooks Pending Fix
Amazon Linux 2 - Core rclone Pending Fix
Amazon Linux 2023 rclone Pending Fix
Amazon Linux 2027 Preview rclone Pending Fix
Amazon Linux 2 - Docker Extra runfinch-finch Pending Fix
Amazon Linux 2023 runfinch-finch Pending Fix
Amazon Linux 2027 Preview runfinch-finch Pending Fix
Amazon Linux 2023 skopeo Pending Fix
Amazon Linux 2027 Preview skopeo Pending Fix
Amazon Linux 2 - Docker Extra soci-snapshotter Pending Fix
Amazon Linux 2023 soci-snapshotter Pending Fix
Amazon Linux 2027 Preview soci-snapshotter Pending Fix
Amazon Linux 2023 yq Pending Fix
Amazon Linux 2027 Preview yq Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H