News

USN-8900-1: Go Networking flaws risk denial of service via HTTP/2

Ubuntu reports two vulnerabilities in the Go Networking package that can cause denial of service on HTTP/2 connections.

UptimeMag editorial team · 8 October 2026 · 1 min read

USN-8900-1: falle in Go Networking, rischio denial of service via HTTP/2

Ubuntu has published security advisory USN-8900-1, covering two vulnerabilities in the Go Networking package (the golang.org/x/net module, used by numerous Go-written services that handle HTTP/2 connections). If you're running Go applications in production on Ubuntu — reverse proxies, API gateways, internal services — it's worth planning an update soon, as both flaws lead to remote denial of service.

The two CVEs

The first, CVE-2022-27664, concerns server error handling after sending a GOAWAY frame while closing an HTTP/2 connection. The bug can leave the connection hanging, and a remote attacker can exploit this to cause a denial of service.

The second, CVE-2022-41723, is a quadratic complexity issue in HPACK header decoding on HTTP/2 streams. A remote attacker can craft requests that cause the service to consume excessive resources, with the same result: denial of service.

The advisory text, as reported by Ubuntu, also flags an issue in text node rendering, whose full description is not included in the excerpt available at the time of writing this article.

What to do

For those using Ubuntu packages that include Go Networking (either directly or as a dependency of other packages), the recommendation is to update according to the patched versions indicated in the official advisory. As with other USNs, it's worth checking which installed packages on your system are affected using:

apt list --upgradable

and then proceeding with:

sudo apt update && sudo apt upgrade

For full details on affected packages and versions, refer to the official advisory page: https://ubuntu.com/security/notices/USN-8900-1

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.