CVE-2026-27141
Not scored
Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
Exploit probability
0.5%
Published
February 26, 2026
Required by
Not available
Last source change
May 15, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2026-4559
View original source
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
05 / REFERENCES