FlawAtlas
Search the atlas
CVE-2021-44716 High

CVE-2021-44716

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

Exploit probability 4.0%
Published January 1, 2022
Required by Not available
Last source change July 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

152 explicit affected versions

Bitnami golang
Go golang.org/x/net
Go stdlib
Go golang.org/x/net/http2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-44716

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

View original source
Open Source Vulnerabilities BIT-golang-2021-44716

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

View original source
Open Source Vulnerabilities GO-2022-0288

An attacker can cause unbounded memory growth in servers accepting HTTP/2 requests.

View original source
Open Source Vulnerabilities GHSA-vc3p-29h2-gpcp

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

View original source

05 / REFERENCES

Further evidence