A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.CreditsJakub Ciolek (https://ciolek.dev)Referenceshttps://go.dev/cl/847186https://go.dev/cl/847308https://go.dev/issue/81742https://groups.google.com/g/golang-announce/c/U2fTuyDJznIhttps://groups.google.com/g/golang-announce/c/ZPwCyRUuGBshttps://pkg.go.dev/vuln/GO-2026-6611