Go fixed CVE-2022-27664, a denial-of-service vulnerability in the HTTP/2 server implementation used by net/http. A remote client could cause a server connection to hang indefinitely when a fatal error interrupted clean shutdown after the server had sent a GOAWAY frame, potentially exhausting server resources through repeated connections.
The fix updated the bundled golang.org/x/net/http2 code and was backported to supported Go 1.18 and 1.19 release branches, including the Go 1.18.6 and 1.19.1 security releases. Go 1.17 did not receive a backport under the project’s release policy; organizations operating affected or unsupported Go versions should upgrade to a supported patched release and assess internet-facing HTTP/2 services for exposure.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Go updated its bundled golang.org/x/net/http2 implementation and created fixes for the Go 1.18 and 1.19 release branches. The issue was closed as completed in commit 29af494.
Go opened an issue for CVE-2022-27664, in which an HTTP/2 server connection could hang indefinitely during shutdown after sending GOAWAY and encountering a fatal error, enabling denial of service.
The golang/go issue tracking CVE-2022-27664 was locked and restricted to collaborators.
A Go project member stated that no backport for Go 1.17 would be provided under the project's release policy.
The Go project released Go 1.19.1 and Go 1.18.6 as security releases.
The Go project released Go 1.18.4 and Go 1.17.12 as security releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
go.dev
Open sourcegroups.google.com
Open sourcegroups.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.