- Description
- When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
- Source
- security@golang.org
- NVD status
- Modified
- Products
- go, http2
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
🛡️ #SUSE #Kubernetes: duas vulnerabilidades críticas (CVE-2026-33814 e CVE-2026-35469) permitem DoS remoto. Saiba mais: -> https://t.co/jTJLH6MZl1 https://t.co/hmb5X7OqTa
@Cezar_H_Linux
19 Jun 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
SUSE released security fixes for CVE-2026-33186 in google-osconfig-agent (authorisation bypass, CVSS 9.1) and CVE-2026-33814 in google-cloud-sap-agent (HTTP/2 DoS, CVSS 7.5) affecting Public Cloud Module 12, according to SUSE advisories. https://t.co/pmI6VI0ClS
@threatcluster
11 Jun 2026
77 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
BREAKING: SUSE issues Go1.26 and Go1.25 security updates fixing DoS CVEs CVE-2026-33811 and CVE-2026-33814 in net and HTTP/2, administrators urged to patch affected SUSE Linux systems immediately. https://t.co/W7csuNa4Id
@threatcluster
15 May 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1C966EF3-C51C-4239-B5FC-C44A5202FEC8",
"versionEndExcluding": "1.25.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "522E4CD0-2B99-4363-9C78-0BAFD988A2D6",
"versionEndExcluding": "1.26.3",
"versionStartIncluding": "1.26.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:http2:*:*:*:*:*:go:*:*",
"matchCriteriaId": "365ED1C8-AAF7-4BA7-949C-6F69AF4CD27E",
"versionEndExcluding": "0.53.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]