Resource exhaustion in Go programming language - CVE-2026-56853
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper timeout handling in net/http when processing new connections for unencrypted HTTP/2 support. A remote attacker can open a connection and withhold the expected HTTP/2 client preface bytes to cause a denial of service.
Only servers configured to support unencrypted HTTP/2 are vulnerable.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Anolis OS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rhc-worker-playbook (Red Hat package)
rhc (Red Hat package)
python3.12-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
golang-github-openprinting-ipp-usb (Red Hat package)
receptor (Red Hat package)
containernetworking-plugins (Red Hat package)
skopeo-doc
skopeo-tests
skopeo
skopeo (Red Hat package)
delve (Red Hat package)
golang
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
golang (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
go-rpm-macros
go-srpm-macros
go-rpm-templates
go-rpm-macros-doc
go-filesystem
git-lfs
git-lfs-doc
automation-controller-cli (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
microshift (Red Hat package)
grafana-pcp (Red Hat package)
grafana (Red Hat package)
osbuild-composer (Red Hat package)
Ansible Automation Platform
Red Hat build of MicroShift
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-56853
rhc-worker-playbook (Red Hat package) - addressed in versions 0.2.3-6.el10_0.1, 0.2.10-2.el10_2
rhc (Red Hat package) - update to 0.2.5-10.el8_10
python3.12-sqlparse (Red Hat package) - update to 0.6.0-1.el9ap
python-sqlparse (Red Hat package) - update to 0.6.0-1.el10ap
golang-github-openprinting-ipp-usb (Red Hat package) - update to 0.9.27-7.el10_2.3
receptor (Red Hat package) - addressed in versions 1.6.8-1.el9ap, 1.6.8-1.el10ap
containernetworking-plugins (Red Hat package) - update to 1.9.0-4.el9_8
skopeo-doc - update to 1.18.2-4
skopeo-tests - update to 1.18.2-4
skopeo - update to 1.18.2-4
skopeo (Red Hat package) - update to 1.22.2-8.el9_8
delve (Red Hat package) - addressed in versions 1.26.1-1.el9_2.1, 1.26.1-1.el9_6.1, 1.26.1-2.el10_0
golang - update to 1.26.6-1
golang-bin - update to 1.26.6-1
golang-shared - update to 1.26.6-1
golang-docs - update to 1.26.6-1
golang-misc - update to 1.26.6-1
golang-src - update to 1.26.6-1
golang-tests - update to 1.26.6-1
golang (Red Hat package) - addressed in versions 1.26.7-1.el9_2, 1.26.7-1.el9_4, 1.26.7-1.el9_8, 1.26.7-1.el10_0, 1.26.7-1.el10_2
cri-o (Red Hat package) - update to 1.35.9-12.rhaos4.22.git4c168db.el9
Ansible Automation Platform - update to 2.7
ignition (Red Hat package) - addressed in versions 2.17.0-2.el9_4.2, 2.21.0-3.el10_0.4
go-rpm-macros - update to 3.6.0-7
go-srpm-macros - update to 3.6.0-7
go-rpm-templates - update to 3.6.0-7
go-rpm-macros-doc - update to 3.6.0-7
go-filesystem - update to 3.6.0-7
git-lfs - update to 3.7.1-6
git-lfs-doc - update to 3.7.1-6
automation-controller-cli (Red Hat package) - addressed in versions 4.8.9-1.el9ap, 4.8.9-1.el10ap
openshift-clients (Red Hat package) - addressed in versions 4.22.0-202609170632.p2.gd0f23b1.assembly.stream.el8, 4.22.0-202609170632.p2.gd0f23b1.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.22.0-202609220430.p2.g9858a61.assembly.stream.el8, 4.22.0-202609220430.p2.g9858a61.assembly.stream.el9
Red Hat build of MicroShift - update to 4.22.16
Red Hat OpenShift Container Platform - update to 4.22.16
microshift (Red Hat package) - update to 4.22.16-202609250657.p0.g3898bb2.assembly.4.22.16.el9
grafana-pcp (Red Hat package) - addressed in versions 5.1.1-15.el9_6.1, 5.1.1-18.el8_10, 5.3.0-1.el10_0.1
grafana (Red Hat package) - addressed in versions 9.2.10-33.el8_10, 10.2.6-23.el9_6, 10.2.6-28.el10_2.5
osbuild-composer (Red Hat package) - addressed in versions 76.1-9.el9_2, 101.3-4.el9_4.6, 132.2-12.el9_6
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Red Hat Enterprise Linux 10 update for golang
- Red Hat Enterprise Linux 10 update for golang
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 10 update for golang-github-openprinting-ipp-usb
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Red Hat Enterprise Linux 10 update for grafana
- Red Hat Enterprise Linux 8 update for grafana-pcp
- Red Hat Enterprise Linux 8 update for rhc
- Red Hat Enterprise Linux 10 update for ignition
- Red Hat Enterprise Linux 9 update for ignition
- Red Hat Enterprise Linux 10 update for delve
- Red Hat Enterprise Linux 10 update for grafana-pcp
- Anolis OS update for golang
- Anolis OS update for skopeo
- Anolis OS update for go-rpm-macros
- Anolis OS update for git-lfs
- Red Hat Enterprise Linux 9 update for delve
- Red Hat Enterprise Linux 9 update for grafana-pcp
- Red Hat Enterprise Linux 9 update for delve
- Red Hat Enterprise Linux 10 update for rhc-worker-playbook
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 10 update for rhc-worker-playbook
- Multiple vulnerabilities in Ansible Automation Platform 2.7 packages
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in Red Hat build of MicroShift 4.22 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22 packages