PatchDay Alert

CVE

CVE-2026-33814

0field notes · 1digest CVSS 7.5


Daily digests

A malformed HTTP/2 SETTINGS_MAX_FRAME_SIZE value can send Go's net/http2 library into an infinite loop, effectively hanging any service built on it. An attacker just needs to send a bad HTTP/2 frame to tie up the process. No authentication required, no user interaction needed.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.