Allocation of Resources Without Limits or Throttling Affecting std/net/http package, versions <1.11.13>=1.12.0-0 <1.12.8


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
51.23% (98th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-STDNETHTTP-14565073
  • published6 Jan 2026
  • disclosed1 Aug 2022
  • creditJonathan Looney of Netflix

Introduced: 1 Aug 2022

CVE-2019-9512  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade std/net/http to version 1.11.13, 1.12.8 or higher.

Overview

std/net/http is a Go standard library package std/net/http

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling.

Go Vulnerability Report:
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service.Servers that accept direct connections from untrusted clients could be remotely made to allocate an unlimited amount of memory, until the program crashes. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

CVSS Base Scores

version 4.0
version 3.1