CVE-2026-49975: HTTP/2 Bomb CVE-2026-49975
Apache HTTP Server: modhttp2 denial of service
Other sources
CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's modhttp leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
— FortiGuard
We’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, including:
nginx
Apache httpd
Microsoft IIS
Envoy
Cloudflare Pingora
The vulnerable behavior exists in each server's default HTTP/2 configuration.
The attack was discovered by Codex, which chained two techniques known to humans for a decade: a compression bomb and a Slowloris-style hold. The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.
A curious search on Shodan revealed 880,000+ websites supporting HTTP/2 and running one of these servers, though many sit behind a CDN, which is much harder to bring down.
A home computer on a 100Mbps connection can render a vulnerable server inaccessible within seconds. Against Apache httpd and Envoy, a single client can consume and hold 32GB of server memory in roughly 20 seconds.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.28.3-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.68-1 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49975?
CVE-2026-49975 has a severity rating of high with a CVSS score of 7.5.
What type of vulnerability is identified in CVE-2026-49975?
CVE-2026-49975 is a denial of service vulnerability affecting Apache HTTP Server's mod_http2.
How do I fix CVE-2026-49975?
To mitigate CVE-2026-49975, apply the latest patches provided by your Apache HTTP Server vendor.
What impact does CVE-2026-49975 have on systems?
CVE-2026-49975 can lead to denial of service, causing affected web servers to crash when processed with malicious HTTP requests.
Which software versions are affected by CVE-2026-49975?
CVE-2026-49975 affects several software versions including Debian Apache2 and Microsoft azl3 httpd 2.4.67-1.