CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
- Published Aug 13, 2026
- CVSS 7.5 high
- 0.6% chance of exploitation in the next 30 days (EPSS)