Bug 2515827 (CVE-2026-56853)

Summary: CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, akostadi, akoudelk, alebedev, alinfoot, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aruklets, asatyam, bbrownin, bniver, bparees, chfoley, ckandaga, cmah, crizzo, dakwon, dhanak, diagrawa, dkeler, dmayorov, doconnor, drosa, dschmidt, dsimansk, dtrifiro, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, flucifre, gbenhaim, ggainey, gmeno, gparvin, groman, hasun, ibolton, jbritton, jburrell, jcantril, jchui, jeder, jfula, jhe, jjoyce, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jpretori, jschluet, jtolenti, juwatts, kingland, kshier, ktsao, lball, lbragsta, lchilton, lgamliel, lhh, mbenjamin, mburns, mdellweg, mgarciac, mhackett, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, niyer, nmoumoul, nyancey, oaljalju, ometelka, osousa, pantinor, pcreech, pgaikwad, pjindal, psrna, ptisnovs, pvasanth, rbryant, rchan, rekumar, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smallamp, sostapov, sseago, stcannon, suppawar, swoodman, syedriko, teagle, thason, tmalecek, tsedmik, twaugh, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vvoronko, watson-tool-maintainers, weaton, wenshen, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTimeout` is not correctly applied during this process. This oversight could allow a remote attacker to maintain open connections indefinitely, potentially leading to a Denial of Service (DoS) by exhausting server resources.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-13 22:21:58 UTC
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

Comment 11 errata-xmlrpc 2026-08-26 13:42:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:60306 https://access.redhat.com/errata/RHSA-2026:60306

Comment 12 errata-xmlrpc 2026-08-26 13:54:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:60305 https://access.redhat.com/errata/RHSA-2026:60305

Comment 13 errata-xmlrpc 2026-08-26 13:55:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:60304 https://access.redhat.com/errata/RHSA-2026:60304

Comment 14 errata-xmlrpc 2026-09-01 05:39:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:61882 https://access.redhat.com/errata/RHSA-2026:61882

Comment 15 errata-xmlrpc 2026-09-02 06:27:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:62405 https://access.redhat.com/errata/RHSA-2026:62405

Comment 16 errata-xmlrpc 2026-09-02 06:34:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62404 https://access.redhat.com/errata/RHSA-2026:62404

Comment 17 errata-xmlrpc 2026-09-02 06:46:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:62407 https://access.redhat.com/errata/RHSA-2026:62407

Comment 18 errata-xmlrpc 2026-09-02 07:10:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:62406 https://access.redhat.com/errata/RHSA-2026:62406

Comment 19 errata-xmlrpc 2026-09-02 11:29:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:62578 https://access.redhat.com/errata/RHSA-2026:62578

Comment 20 errata-xmlrpc 2026-09-02 12:18:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:62602 https://access.redhat.com/errata/RHSA-2026:62602

Comment 21 errata-xmlrpc 2026-09-02 14:07:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:62631 https://access.redhat.com/errata/RHSA-2026:62631

Comment 22 errata-xmlrpc 2026-09-02 16:39:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:62754 https://access.redhat.com/errata/RHSA-2026:62754

Comment 23 errata-xmlrpc 2026-09-02 16:56:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:62753 https://access.redhat.com/errata/RHSA-2026:62753

Comment 24 errata-xmlrpc 2026-09-02 19:13:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62803 https://access.redhat.com/errata/RHSA-2026:62803

Comment 25 errata-xmlrpc 2026-09-03 05:31:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:63022 https://access.redhat.com/errata/RHSA-2026:63022

Comment 26 errata-xmlrpc 2026-09-03 23:34:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:63124 https://access.redhat.com/errata/RHSA-2026:63124

Comment 27 errata-xmlrpc 2026-09-03 23:43:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:63119 https://access.redhat.com/errata/RHSA-2026:63119

Comment 28 errata-xmlrpc 2026-09-04 00:43:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:63332 https://access.redhat.com/errata/RHSA-2026:63332

Comment 29 errata-xmlrpc 2026-09-04 01:00:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:63163 https://access.redhat.com/errata/RHSA-2026:63163

Comment 30 errata-xmlrpc 2026-09-08 02:27:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:64777 https://access.redhat.com/errata/RHSA-2026:64777

Comment 31 errata-xmlrpc 2026-09-08 03:16:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:64786 https://access.redhat.com/errata/RHSA-2026:64786

Comment 32 errata-xmlrpc 2026-09-08 04:39:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:64818 https://access.redhat.com/errata/RHSA-2026:64818