Maintainers disclosed two high-severity HTTP/2 denial-of-service flaws that can be triggered by malicious protocol frames in widely used implementations. In nghttp2, CVE-2026-27135 causes an assertion failure after session termination has begun if the library continues processing incoming data and encounters a malformed frame that leads to FRAME_SIZE_ERROR. The vulnerable paths include ALTSVC, PRIORITY_UPDATE, and user-defined extension frames, with the issue fixed in nghttp2 v1.68.1 by adding missing internal state validation; no workaround was provided.
In Go's HTTP/2 transport, CVE-2026-33814 allows a malicious server to force an infinite loop of CONTINUATION frame writes by sending a SETTINGS frame with SETTINGS_MAX_FRAME_SIZE=0, creating a remote denial-of-service condition against HTTP/2 clients. The flaw, tracked as Go issue #78476 and later documented by Microsoft with a CVSS 7.5 rating, was fixed by validating received SETTINGS_MAX_FRAME_SIZE values before use, underscoring continued risk from improper state and bounds checking in HTTP/2 frame handling.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published an advisory for CVE-2026-33814, describing an infinite-loop denial-of-service vulnerability in golang.org/x/net's HTTP/2 transport caused by an invalid SETTINGS_MAX_FRAME_SIZE value. The advisory rated the issue 7.5 CVSS and listed the release date as May 10, 2026.
Red Hat released advisories for CVE-2026-27135 affecting nghttp2 and Node.js-related packages across Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, RHEL 10.0 EUS, and JBoss Core Services. The earliest fixes listed were RHSA-2026:7080 for RHEL 10 nodejs22 and RHSA-2026:7123 for RHEL 8 nodejs:22 on April 8, 2026.
Go issue 78476 was opened to track CVE-2026-33814, a denial-of-service vulnerability in net/http/internal/http2 where a malicious SETTINGS frame with SETTINGS_MAX_FRAME_SIZE set to 0 can trigger an infinite loop of CONTINUATION frame writes. The report credits Marwan Atia and notes the flaw was fixed by validating received SETTINGS_MAX_FRAME_SIZE values.
The nghttp2 project fixed CVE-2026-27135 in version 1.68.1 by adding state validation to the affected code paths. The advisory stated there is no workaround and recommended patching even if asserts are disabled at build time.
A security advisory disclosed CVE-2026-27135 in nghttp2, a high-severity denial-of-service issue caused by missing internal state validation after session termination begins. The flaw can lead to an assertion failure when malformed frames are processed after termination is initiated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcemsrc.microsoft.com
Open sourcego.dev
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.