VDB

CVE-2026-56853

CVE-2026-56853 PUBLISHED CVSS 7.5 HIGH

Reported by Go · Published August 13, 2026

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Go standard librarynet/http0, 1.26.0-0, 1.27.0-0
chainguardcrossplane-provider-aws-ecs-fips0
chainguardazuredisk-csi-fips-1.320
chainguardcoredns-1.140
chainguardkube-metrics-adapter-fips0
chainguardistio-fips-1.30*
chainguardazuredisk-csi-fips-1.330
chainguardnri-jmx-fips*, *
chainguardrancher-fleet0, 0
chainguardvirt-operator-fips-1.70
chainguardcortex0
chainguardcontour-1.330
chainguardcrossplane-provider-aws-lightsail0
wolficertificate-transparency0, 0, 0
chainguardcilium-certgen-fips-0.1*
wolfiargocd-image-updater0, 0, 0
chainguardargo-rollouts0
chainguardcloud-provider-azure-1.350
chainguardaws-ebs-csi-driver-1.560
chainguardexternal-secrets-operator-fips-2.40

…and 2815 more

Timeline

  • Aug 13, 2026 CVE Published
  • Aug 14, 2026 CVE Updated
  • Aug 15, 2026 Coalition ESS Score
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›