{"id":"CVE-2026-56853","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-56853","summary":"Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http","details":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.","published":"2026-08-13T21:43:54Z","modified":"2026-08-14T09:41:57.819455891Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"stdlib","fixedVersion":"1.25.13"}],"fix":null,"references":[{"type":"REPORT","url":"https://go.dev/issue/80205"},{"type":"FIX","url":"https://go.dev/cl/795540"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T09:41:57.819455891Z"}}