See https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-3323837 that mentions: Denial of Service (DoS) Affecting [golang.org/x/net/http2](https://security.snyk.io/package/golang/golang.org%2Fx%2Fnet%2Fhttp2) package, versions <0.7.0 It appears that updating the package to `0.7.0` resolves the vulnerability.