{"schema_version":"1.9.0","id":"GO-2026-6609","published":"2026-10-08T22:31:09Z","modified":"2026-10-08T22:45:08.423478605Z","aliases":["CVE-2026-78667"],"summary":"Lack of limit on size of parsed Range headers in net/http","details":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.","affected":[{"package":{"name":"stdlib","ecosystem":"Go","purl":"pkg:golang/stdlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.26.9"},{"introduced":"1.27.0-0"},{"fixed":"1.27.2"}]}],"ecosystem_specific":{"imports":[{"path":"net/http","symbols":["ServeContent","ServeFile","ServeFileFS","fileHandler.ServeHTTP","fileTransport.RoundTrip","parseRange"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6609.json"}}],"references":[{"type":"FIX","url":"https://go.dev/cl/847309"},{"type":"REPORT","url":"https://go.dev/issue/81858"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6609"},"credits":[{"name":"Jakub Ciolek (https://ciolek.dev)"}]}