CVE-2026-49975
Apache HTTP Server: mod_http2 denial of service
Description
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
In plain language
AI Worth attentionCVE-2026-49975 is a denial-of-service weakness in Apache HTTP Server’s mod_http that can crash or seriously slow the server when it receives malicious requests; if you run Apache HTTP Server in the affected versions, you should act soon, but this is not confirmed as widely exploited yet.
What to do
- Update Apache HTTP Server to a version outside 2.4.17 through 2.4.67 (ask your IT person to apply the vendor patch). 2) If you can’t update immediately, ask your IT person to temporarily reduce exposure (for example, restrict direct access to the affected endpoint paths from the public internet). 3) If you’re behind a reverse proxy or CDN, confirm with your provider/IT team whether requests hitting the affected component are filtered or mitigated.
CVSS Vector Breakdown
Exploitability
AV:NAttack VectorNetwork
AC:LAttack ComplexityLow
PR:NPrivileges RequiredNone
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:NConfidentialityNone
I:NIntegrityNone
A:HAvailabilityHigh
Weaknesses
Affected Products
Microsoft Corp
commercial·USaka microsoft corporation
Cloudflare, Inc
commercial·USaka cloudflare inc
Apache Software Foundation
oss-project·USaka apache foundation
NGINX Inc.
commercial·USaka nginx, njs, nginx plus
apache
oss-project·USaka apache httpd, apache http server
and 2 more affected products View all →
Exploitability
Official Patch Available
References
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
blog.calif.io
https://github.com/nginx/nginx/releases/tag/release-1.29.8
github.com
https://github.com/nginx/nginx/pull/1116
github.com
and 23 more references View all →
News mentions
7- Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attacken-us·SecurityWeek· Patch NetScaler ADC ddos-botnet
- MEGANews. Cамые важные события в мире инфосека за июньru-ru·Хакер (xakep.ru)· Incident App Store data-breach
- ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Storiesen·The Hacker News· Roundup Anthropic Claude phishing
- HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risken·Dark Reading· PoC nginx ddos-botnet
- Rapid7en·Rapid7 Blog· Roundup Windows Nightmare Eclipse
- DoS-атака HTTP/2 Bomb за считаные секунды выводит из строя веб-серверыru-ru·Хакер (xakep.ru)· PoC HTTP/2 ddos-botnet
- New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minuteen-us·BleepingComputer· PoC HTTP/2 implementations (nginx, Apache httpd, Envoy, IIS, Cloudflare Pingora) ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-49975 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
