Go project advisory: HTTP/2 server memory exhaustion fixed in golang.org/x/net v0.60.0
The Go project published a security advisory for golang.org/x/net v0.60.0, which fixes several vulnerabilities, including memory exhaustion in HTTP/2 servers related to Trailer headers.
Source: Encaminhado: vulnerabilidades em golang.org/x/net (seclists.org). Text prepared with AI from this source.
What happened and what to do
On 8 October 2026, the Go project tagged golang.org/x/net v0.60.0 to fix security issues. One of them is memory exhaustion in HTTP/2 servers related to Trailer headers, which can let a process consume memory without limit. The advisory was forwarded to the oss-sec list, where Alan Coopersmith published it.
A practical response starts by inventorying which of the client's Go services use golang.org/x/net, directly or indirectly, and which versions they run. The upgrade to v0.60.0 should then enter the build pipeline, with regression tests and staged rollout. Until the fix is in production, it is worth monitoring memory use per service, setting alerts for abnormal growth, and evaluating header size limits at the reverse proxy. This can be automated with metric collection, dashboards and routines that flag exposed services.
How the consultancy can help
Diagnosis of Go dependencies and HTTP/2 server exposure, an upgrade plan to v0.60.0 and memory monitoring, with scoped implementation and ongoing operation in the client's environment.
Next step
Send a short description of your situation, including the Go services and infrastructure involved, and receive a scoped proposal for diagnosis and implementation.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal