← Vulnerability feed

Vulnerability record · CVE-2026-33814 · published 7 May 2026

CVE-2026-33814: Golang go vulnerability

Golang · Go

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

7.5 CVSS 3.1 High EPSS 0.78% · top 45.8% CWE-835 · CWE-835CWE-606 · CWE-606
7.5CVSS 3.1 base score
0.78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
70References
18 Sep 2026Last modified by NVD

Description

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://go.dev/cl/761581 Patch
https://go.dev/cl/761640 Patch
https://go.dev/issue/78476 Issue TrackingMailing List
https://groups.google.com/g/golang-announce/c/qcCIEXso47M Release Notes
https://pkg.go.dev/vuln/GO-2026-4918 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:22112
https://access.redhat.com/errata/RHSA-2026:22120
https://access.redhat.com/errata/RHSA-2026:22121
https://access.redhat.com/errata/RHSA-2026:23262
https://access.redhat.com/errata/RHSA-2026:23264
https://access.redhat.com/errata/RHSA-2026:33120
https://access.redhat.com/errata/RHSA-2026:33123
https://access.redhat.com/errata/RHSA-2026:33142
https://access.redhat.com/errata/RHSA-2026:33150
https://access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:37387
https://access.redhat.com/errata/RHSA-2026:42644
https://access.redhat.com/errata/RHSA-2026:43692
https://access.redhat.com/errata/RHSA-2026:49702
https://access.redhat.com/errata/RHSA-2026:49712
https://access.redhat.com/errata/RHSA-2026:50205
https://access.redhat.com/errata/RHSA-2026:54274
https://access.redhat.com/errata/RHSA-2026:54283
https://access.redhat.com/errata/RHSA-2026:54284
https://access.redhat.com/errata/RHSA-2026:54285
https://access.redhat.com/errata/RHSA-2026:54286
https://access.redhat.com/errata/RHSA-2026:54287
https://access.redhat.com/errata/RHSA-2026:56854
https://access.redhat.com/errata/RHSA-2026:56912
https://access.redhat.com/errata/RHSA-2026:57191
https://access.redhat.com/errata/RHSA-2026:57194
https://access.redhat.com/errata/RHSA-2026:57365
https://access.redhat.com/errata/RHSA-2026:57367
https://access.redhat.com/errata/RHSA-2026:57408
https://access.redhat.com/errata/RHSA-2026:57545
https://access.redhat.com/errata/RHSA-2026:57649
https://access.redhat.com/errata/RHSA-2026:57845
https://access.redhat.com/errata/RHSA-2026:59833
https://access.redhat.com/errata/RHSA-2026:60023
https://access.redhat.com/errata/RHSA-2026:60025

Track CVE-2026-33814 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2020-0601Windows CryptoAPI ECC certificate validation spoofing flawWindows CryptoAPI (Crypt32.dll) improperly validates Elliptic Curve Cryptography certificates, allowing a spoofed code-signing certificate to be trus…KEVEPSS 89%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed10.0CVE-2025-68121Golang go improper certificate validation vulnerabilityDuring session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the r…EPSS 0.86%9.8CVE-2026-27143Golang go vulnerabilityArithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid …EPSS 0.66%9.8CVE-2024-24790Golang go vulnerabilityThe various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which woul…EPSS 2.0%9.8CVE-2023-39320Golang go code injection vulnerabilityThe go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "…EPSS 1.8%9.8CVE-2023-29404Golang go code injection vulnerabilityThe go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…EPSS 1.8%9.8CVE-2023-29405Golang go injection vulnerabilityThe go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2026-33814), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.