External risk intelligence

HTTP/2 Server Connection Flow Control Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-78663

This vulnerability affects HTTP/2 server implementations. HTTP/2 servers are designed to handle incoming connections directly from the internet to serve web traffic or APIs. As a core networking component exposed to public-facing traffic by design, this functionality is typically internet-facing.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects HTTP/2 server implementations by allowing a malicious client to bypass flow control limits. While the total buffered data remains constrained, this bypass could potentially impact server stability or resource availability. The main concern is confirming relevance and exposure.

  • Server flow control bypass is possible.
  • It could impact server stability and resources.
  • Confirm relevance and exposure for your systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to an HTTP/2 server. By manipulating connection flow control, specifically by resetting streams and then reading buffered data, an attacker can cause the server to refund flow control limits twice. This allows them to bypass the configured maximum buffer size for a connection, potentially leading to denial-of-service or other impacts on the server's ability to handle traffic.

  • No authentication or special privileges needed.
  • Resets streams and reads buffered data.
  • Bypass flow control limits.

Live Threat

Current exploitation, exposure, and threat context

A malicious client could exploit this vulnerability by sending crafted requests to bypass the configured connection-level flow control limits. This occurs when the server refunds flow control credit twice for the same data, potentially allowing a larger amount of data to be buffered than intended. While total buffered data remains constrained by other limits, this specific bypass could impact service stability and resource utilization.

  • Connection flow control buffer.
  • Client initiates stream reset and reads data.
  • Service instability and resource exhaustion.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects HTTP/2 server implementations, a core networking component often exposed to the internet. Responsibility likely falls to infrastructure, platform, or network/security teams who manage these services. The first practical step is to identify all instances of the affected technology, confirm their exposure and criticality, and then assign ownership for remediation planning.

  • Infrastructure and Platform Teams
  • Verify internet-facing exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the HTTP/2 server software affected by CVE-2026-78663?

This CVE concerns the HTTP/2 implementation used in Go, a popular programming language for building high-performance network services. Developers use this HTTP/2 component to create robust web servers and APIs capable of handling multiple requests concurrently over a single connection.

How does this CVE-2026-78663 vulnerability work?

The flaw is categorized as CWE-675, which involves multiple resource releases. In this context, the server mistakenly refunds connection-level flow control credits twice for the same data. By triggering this accounting error, a client can bypass configured buffer limits designed to prevent memory exhaustion, potentially forcing the server to buffer more data than it should.

Do I need to worry if I am not resetting streams?

The vulnerability requires a specific sequence: the client must send data, initiate a stream reset, and then read the buffered data. Simply connecting to the server or using standard, non-malicious traffic does not trigger the flow control bypass. The bug relies on this particular interaction to trick the server's accounting logic.

Is my server at risk if it is behind a firewall?

Halo Surface Signal notes that HTTP/2 servers are core networking components often exposed to the internet by design to handle public traffic. While the impact is generally higher for internet-facing systems, you should evaluate if your specific environment allows untrusted clients to reach this HTTP/2 server functionality, as internal exposure could still be relevant.

How should I respond to CVE-2026-78663?

Begin by identifying all services in your environment that utilize the affected Go HTTP/2 implementation. Once located, verify their network exposure and determine which applications handle traffic from untrusted sources. Finally, coordinate with your infrastructure or platform teams to establish ownership and prioritize updating the affected software to a patched version.

References