VDB
CVE-2026-56853
CVE-2026-56853
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published August 13, 2026
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go standard library | net/http | 0, 1.26.0-0, 1.27.0-0 |
| chainguard | crossplane-provider-aws-ecs-fips | 0 |
| chainguard | azuredisk-csi-fips-1.32 | 0 |
| chainguard | coredns-1.14 | 0 |
| chainguard | kube-metrics-adapter-fips | 0 |
| chainguard | istio-fips-1.30 | * |
| chainguard | azuredisk-csi-fips-1.33 | 0 |
| chainguard | nri-jmx-fips | *, * |
| chainguard | rancher-fleet | 0, 0 |
| chainguard | virt-operator-fips-1.7 | 0 |
| chainguard | cortex | 0 |
| chainguard | contour-1.33 | 0 |
| chainguard | crossplane-provider-aws-lightsail | 0 |
| wolfi | certificate-transparency | 0, 0, 0 |
| chainguard | cilium-certgen-fips-0.1 | * |
| wolfi | argocd-image-updater | 0, 0, 0 |
| chainguard | argo-rollouts | 0 |
| chainguard | cloud-provider-azure-1.35 | 0 |
| chainguard | aws-ebs-csi-driver-1.56 | 0 |
| chainguard | external-secrets-operator-fips-2.4 | 0 |
…and 2815 more
Timeline
- Aug 13, 2026 CVE Published
- Aug 14, 2026 CVE Updated
- Aug 15, 2026 Coalition ESS Score
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score