{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-27141","assignerOrgId":"1bb62c36-49e3-4200-9d77-64a1400537cc","state":"PUBLISHED","assignerShortName":"Go","dateReserved":"2026-02-17T19:57:28.435Z","datePublished":"2026-02-26T18:50:31.830Z","dateUpdated":"2026-02-27T19:11:57.260Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1bb62c36-49e3-4200-9d77-64a1400537cc","shortName":"Go","dateUpdated":"2026-02-26T18:50:31.830Z"},"title":"Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net","descriptions":[{"lang":"en","value":"Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic"}],"affected":[{"vendor":"golang.org/x/net","product":"golang.org/x/net/http2","collectionURL":"https://pkg.go.dev","packageName":"golang.org/x/net/http2","versions":[{"version":"0.50.0","lessThan":"0.51.0","status":"affected","versionType":"semver"}],"programRoutines":[{"name":"typeFrameParser"},{"name":"ClientConn.Close"},{"name":"ClientConn.Ping"},{"name":"ClientConn.RoundTrip"},{"name":"ClientConn.Shutdown"},{"name":"ConfigureServer"},{"name":"ConfigureTransport"},{"name":"ConfigureTransports"},{"name":"ConnectionError.Error"},{"name":"ErrCode.String"},{"name":"FrameHeader.String"},{"name":"FrameType.String"},{"name":"FrameWriteRequest.String"},{"name":"Framer.ReadFrame"},{"name":"Framer.ReadFrameForHeader"},{"name":"Framer.ReadFrameHeader"},{"name":"Framer.WriteContinuation"},{"name":"Framer.WriteData"},{"name":"Framer.WriteDataPadded"},{"name":"Framer.WriteGoAway"},{"name":"Framer.WriteHeaders"},{"name":"Framer.WritePing"},{"name":"Framer.WritePriority"},{"name":"Framer.WritePriorityUpdate"},{"name":"Framer.WritePushPromise"},{"name":"Framer.WriteRSTStream"},{"name":"Framer.WriteRawFrame"},{"name":"Framer.WriteSettings"},{"name":"Framer.WriteSettingsAck"},{"name":"Framer.WriteWindowUpdate"},{"name":"GoAwayError.Error"},{"name":"ReadFrameHeader"},{"name":"Server.ServeConn"},{"name":"Setting.String"},{"name":"SettingID.String"},{"name":"SettingsFrame.ForeachSetting"},{"name":"StreamError.Error"},{"name":"Transport.CloseIdleConnections"},{"name":"Transport.NewClientConn"},{"name":"Transport.RoundTrip"},{"name":"Transport.RoundTripOpt"},{"name":"bufferedWriter.Flush"},{"name":"bufferedWriter.Write"},{"name":"bufferedWriterTimeoutWriter.Write"},{"name":"chunkWriter.Write"},{"name":"clientConnPool.GetClientConn"},{"name":"connError.Error"},{"name":"dataBuffer.Read"},{"name":"duplicatePseudoHeaderError.Error"},{"name":"gzipReader.Close"},{"name":"gzipReader.Read"},{"name":"headerFieldNameError.Error"},{"name":"headerFieldValueError.Error"},{"name":"netHTTPClientConn.Close"},{"name":"netHTTPClientConn.RoundTrip"},{"name":"noDialClientConnPool.GetClientConn"},{"name":"noDialH2RoundTripper.NewClientConn"},{"name":"noDialH2RoundTripper.RoundTrip"},{"name":"pipe.Read"},{"name":"priorityWriteSchedulerRFC7540.CloseStream"},{"name":"priorityWriteSchedulerRFC7540.OpenStream"},{"name":"priorityWriteSchedulerRFC9218.OpenStream"},{"name":"pseudoHeaderError.Error"},{"name":"requestBody.Close"},{"name":"requestBody.Read"},{"name":"responseWriter.Flush"},{"name":"responseWriter.FlushError"},{"name":"responseWriter.Push"},{"name":"responseWriter.SetReadDeadline"},{"name":"responseWriter.SetWriteDeadline"},{"name":"responseWriter.Write"},{"name":"responseWriter.WriteHeader"},{"name":"responseWriter.WriteString"},{"name":"roundRobinWriteScheduler.OpenStream"},{"name":"serverConn.CloseConn"},{"name":"serverConn.Flush"},{"name":"stickyErrWriter.Write"},{"name":"transportResponseBody.Close"},{"name":"transportResponseBody.Read"},{"name":"unencryptedTransport.RoundTrip"},{"name":"writeData.String"}],"defaultStatus":"unaffected"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-476: NULL Pointer Dereference"}]}],"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27141"},{"url":"https://go.dev/cl/746180"},{"url":"https://go.dev/issue/77652"},{"url":"https://pkg.go.dev/vuln/GO-2026-4559"}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-476","lang":"en","description":"CWE-476 NULL Pointer Dereference"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-02-27T19:11:24.117207Z","id":"CVE-2026-27141","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-27T19:11:57.260Z"}}]}}