{"id":"GO-2026-6089","summary":"Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http","details":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.","aliases":["CVE-2026-56853"],"modified":"2026-08-14T09:41:57.819455891Z","published":"2026-08-13T21:43:54Z","related":["CGA-gx4x-f625-2c45"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6089","review_status":"REVIEWED"},"references":[{"type":"REPORT","url":"https://go.dev/issue/80205"},{"type":"FIX","url":"https://go.dev/cl/795540"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"}],"affected":[{"package":{"name":"stdlib","ecosystem":"Go","purl":"pkg:golang/stdlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.13"},{"introduced":"1.26.0-0"},{"fixed":"1.26.6"},{"introduced":"1.27.0-0"},{"fixed":"1.27.0-rc.3"}]}],"ecosystem_specific":{"imports":[{"symbols":["ListenAndServe","ListenAndServeTLS","Serve","ServeTLS","Server.ListenAndServe","Server.ListenAndServeTLS","Server.Serve","Server.ServeTLS","conn.readRequest","conn.serve"],"path":"net/http"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6089.json"}}],"schema_version":"1.9.0"}