CVE-2026-33814: Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Overview
- Severity
- High (CVSS 7.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-May
- Released
- 2026-05-10
- Last Updated
- 2026-06-03
- EPSS Score
- 0.56% (percentile: 42.4%)
Affected Products (54)
Other
- 21203-17084
- 21206-17084
- 20981-17084
- 17591-17084
- 21177-17084
- 20985-17084
- 20986-17084
- 21319-17084
- 21276-17084
- 20991-17084
- 21271-17084
- 20993-17084
- 21272-17084
- 21132-17084
- 21278-17084
- 21315-17084
- 21281-17084
- 21284-17084
- 21252-17084
- 21007-17084
- 21008-17084
- 21299-17084
- 21011-17084
- 17793-17084
- 21273-17084
- 21274-17084
- 21013-17084
- 21014-17084
- 20966-17084
- 21015-17084
- 19324-17084
- 21016-17084
- 21280-17084
- 21020-17084
- 20968-17084
- 21107-17084
- 21425-17084
- 21419-17084
- 21383-17084
- 20984-17084
- 19322-17084
- 20582-17084
- 21256-17084
- 21424-17084
- 21426-17084
- 21407-17084
- 21427-17084
- 21428-17084
- 21429-17084
- 21397-17084
- ... and 1 more
Open Source Software
- azl3 coredns 1.11.4-15 on Azure Linux 3.0
- azl3 etcd 3.5.28-1 on Azure Linux 3.0
- azl3 telegraf 1.31.0-19 on Azure Linux 3.0
Revision History
- 2026-05-10: Information published.
- 2026-05-11: Information published.
- 2026-05-13: Information published.
- 2026-05-14: Information published.
- 2026-05-15: Information published.
- 2026-05-16: Information published.
- 2026-05-19: Information published.
- 2026-05-19: Information published.
- 2026-05-26: Information published.
- 2026-05-30: Information published.
- 2026-06-03: Information published.