When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. | |
| Title | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-08-13T21:58:53.092Z
Reserved: 2026-06-23T15:10:49.352Z
Link: CVE-2026-56853
No data.
Status : Received
Published: 2026-08-13T22:17:22.093
Modified: 2026-08-13T22:17:22.093
Link: CVE-2026-56853
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.