The Go project marked v0.60.0 of golang.org/x/net to fix vulnerabilities, including memory exhaustion in an HTTP/2 server caused by Trailer headers. The advisory was forwarded through the oss-sec feed on October 8, 2026.
The Go project announced version v0.60.0 of golang.org/x/net with security fixes. One listed issue is memory exhaustion in an HTTP/2 server, caused by Trailer headers sent in certain requests. The advisory was forwarded through the oss-sec feed on October 8, 2026, with the original post by Alan Coopersmith, and the available text does not reproduce the full list of issues.
For teams that maintain Go services, the practical step is to check whether the application depends on this module, update to the fixed version, and consult the original advisory for details and exposure conditions. Rota Nacional does not patch third-party libraries and does not solve this engineering problem.
If your team uses AI to study the advisory, remove credentials, identifiers and personal data from logs and configuration excerpts before pasting the material into the tool.