When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
Update golang.org/x/net/golang.org/x/net/http2 to 0.53.0; Go standard library/net/http to 1.25.10 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanInfinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net affects golang.org/x/net/golang.org/x/net/http2 (generic), Go standard library/net/http (generic). Severity is high. When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| golang.org/x/net/golang.org/x/net/http2generic | >=0 <0.53.0 | 0.53.0 |
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
Update golang.org/x/net/golang.org/x/net/http2 to 0.53.0; Go standard library/net/http to 1.25.10 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanInfinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net affects golang.org/x/net/golang.org/x/net/http2 (generic), Go standard library/net/http (generic). Severity is high. When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| golang.org/x/net/golang.org/x/net/http2generic | >=0 <0.53.0 | 0.53.0 |
| Go standard library/net/httpgeneric |
|---|
| >=0 <1.25.10 || >=1.26.0-0 <1.26.3 |
| 1.25.10, 1.26.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Go standard library/net/httpgeneric |
|---|
| >=0 <1.25.10 || >=1.26.0-0 <1.26.3 |
| 1.25.10, 1.26.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard