VendorsGolanghttp2any version
Vulnerabilities

Golang http2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-41723
Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
Published 2023-02-28 · Modified
7.5EPSS 0.046
CVE-2023-39325
HTTP/2 rapid reset can cause excessive work in net/http
Published 2023-10-11 · Modified
7.5EPSS 0.038
CVE-2026-33814
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Published 2026-05-07 · Modified
7.5EPSS 0.009
CVE-2022-41717
Excessive memory growth in net/http and golang.org/x/net/http2
Published 2022-12-08 · Modified
5.3EPSS 0.058