CVE-2026-78660EPSS p21.2%
CVE-2026-78660CVE-2026-78660
Description
Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 0.30% probability of exploitation · percentile 21.2% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |