Download Latest Version v1.75.0 source code.zip (502.8 kB) Google Add to Preferred Sources
Home / v1.75.0
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-10-05 17.6 kB
v1.75.0 source code.tar.gz 2026-10-05 433.3 kB
v1.75.0 source code.zip 2026-10-05 502.8 kB
Totals: 3 Items   953.7 kB 0

v1.75.0 improves HTTP parsing and serialization, URI processing, cached file serving, and client connection handling. It also fixes cookie injection, request/response framing problems, and excessive CPU or memory consumption from certain inputs.

Go 1.26 or newer is now required. #2395

Performance improvements

  • HTTP parsing: request headers are parsed and validated in one pass, with common methods and HTTP/1.1 recognized directly. Header values, case conversion, host validation, and control-byte checks process multiple bytes at a time. The parser also avoids repeatedly scanning the same incomplete header block when data arrives in small reads. #2413, #2414, #2428, #2423, #2412, #2438
  • HTTP writing: fewer header and response copies, cached serialized Server and Date lines, faster HTTP date formatting, and fewer flushes around chunked trailers. Large buffered responses can use writev on TCP and Unix connections; TLS and streamed bodies retain the buffered path. #2425, #2415, #2434, #2426, #2433
  • URI processing: memoized authority parsing, a fast path for /, faster quoting and validation, and linear-time path normalization. #2411, #2423, #2453
  • Static files: cached files of up to 8 KiB can be served from memory, avoiding a file read on each cache hit and releasing the file descriptor. The new small-file content cache is bounded to 4096 files, or at most 32 MiB per FS; the existing cache metadata is separate. Changes to these files become visible after cache expiration (CacheDuration, 10 seconds by default). #2446
  • Client and server overhead: clients avoid redundant deadline updates when no timeout is active. The opt-in Server.LazyRequestTime avoids reading the clock until RequestCtx.Time() is called; with this option, the returned time is the time of the first call. The benchmark comparison below uses the default setting. #2439, #2404

Security fixes and hardening

  • Streamed request bodies are drained before connection reuse. With StreamRequestBody enabled, the server drains unread body data before reusing the connection, with a 256 KiB drain limit, or closes the connection when safe draining is not possible. Responses are flushed before draining so early replies reach clients still uploading, and response streams can consume the request body before its remaining size is checked. #2368, #2461
  • Rejected 100-continue requests close the connection. A denied request could previously leave its body unread and have those bytes interpreted as the next request, desynchronizing a reused connection. #2450
  • Cookie setters prevent additional-cookie injection. RequestHeader.SetCookie and its byte variants now sanitize semicolons in names and values, so one logical cookie cannot become multiple cookies on the wire. #2393
  • Bounded zstd decoding limits decoder memory demand as well as output. A small compressed frame could previously declare a large decoder window even when a decoded-body limit was configured. Positive BodyUnzstdWithLimit limits now select a memory-limited decoder, with caps rounded up in 8 MiB buckets; exceeding the decoder limit returns ErrBodyTooLarge. #2407
  • Path normalization avoids quadratic work. Repeated separators and dot segments are processed in linear time, reducing the CPU amplification possible with crafted request targets. Incomplete headers arriving one byte at a time also avoid repeated full-block scans. #2453, #2413
  • Bodyless responses preserve framing. HEAD and status-defined bodyless responses no longer emit trailer bytes that can be mistaken for the next response. Serialization suppresses forbidden Content-Length and Transfer-Encoding on 1xx/204 responses. Explicit content-type metadata and permitted 304 metadata remain supported. #2441, #2447, #2457
  • Pipeline clients gain a response-body limit and better failure cleanup. Set the new PipelineClient.MaxResponseBodySize to a positive value to reject oversized responses, including with Response.StreamBody; the default remains unlimited. Idle workers now retire after errors, abandoned requests release their streams, and failed connection establishment is throttled. #2427, #2458

Argument sorting now honors any negative comparator result in Args.Sort and Args.SortKeys, and static-file serving rejects zero-length suffix byte ranges (bytes=-0) with 416 Range Not Satisfiable. #2459, #2460

Other significant changes include opt-in ETags for FS, a net/http request conversion function, improved adaptor handling of flushes, aborts and trailers, and fixes to shutdown and per-IP connection lifetimes. #2399, #2104, #2429, #2445, #2352, #2402

Benchmark results

Compared v1.74.0 with master 6141d3a on Ubuntu 26.04, an AMD EPYC 9454, and Go 1.27.1. Each benchmark has ten samples per revision, run alternately with the same inputs and CPU affinity. Negative percentages mean less time per operation. All rows below have p < 0.001.

Benchmark v1.74.0 Release candidate Time/op change
Minimal GET, pipeline depth 64 484.30 ns 278.05 ns -42.6%
Browser-shaped GET, pipeline depth 16 1.080 µs 722.55 ns -33.1%
Request-header parsing 561.80 ns 348.15 ns -38.0%
Response-header parsing 466.95 ns 277.55 ns -40.6%
Request-header writing 49.84 ns 37.45 ns -24.8%
Response-header writing 68.64 ns 40.99 ns -40.3%
Cached 1 KiB file, directory 2.324 µs 611.85 ns -73.7%
Cached 1 KiB file, os.DirFS 3.805 µs 612.30 ns -83.9%
URI path with query string 91.39 ns 46.06 ns -49.6%
HTTP date formatting 108.25 ns 28.59 ns -73.6%
Trickled ~4 KiB headers, one byte per read 1385.784 µs 191.257 µs -86.2%
8 KiB path of repeated / 352.529 µs 54.330 µs -84.6%
~8 KiB path of repeated /a/.. 96.733 µs 22.253 µs -77.0%
TCP client/server round trips, small response 5.193 µs 5.030 µs -3.1%
TCP client/server round trips, 64 KiB response 15.302 µs 13.478 µs -11.9%

The pipelined serving and file benchmarks use an in-memory connection with writes discarded. The two TCP rows include real loopback networking. These results describe the selected workloads; TCP gains are smaller than the gains in parsing and serialization. Server.LazyRequestTime remains disabled in this comparison.

What's Changed

Compatibility

Security and hardening

Performance

Features

Fixes

Documentation, tests and tooling

Dependency updates

New Contributors

Full Changelog: https://github.com/valyala/fasthttp/compare/v1.74.0...v1.75.0

Source: README.md, updated 2026-10-05