FG-IR-26-163: HTTP/2 Bomb CVE-2026-49975
Published Aug 12, 2026
·Updated
CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's modhttp leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Affected Software
14 affected components
Fortinet FortiPAM>=1.9.0<=1.9.1
Fortinet FortiPAM>=1.8
Fortinet FortiPAM>=1.7
Fortinet FortiPAM>=1.6
Fortinet FortiPAM>=1.5
Fortinet FortiPAM>=1.4
Fortinet FortiPAM>=1.3
Fortinet FortiPAM>=1.2
Fortinet FortiPAM>=1.1
Fortinet FortiPAM>=1.0
Fortinet FortiProxy>=7.6.0<=7.6.6
Fortinet FortiProxy>=7.4.0<=7.4.14
Fortinet FortiProxy>=7.2
Fortinet FortiSwitchManager>=7.2.0<=7.2.9
Event History
Aug 12, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-163?
The severity of FG-IR-26-163 is medium with a score of 5.8.
2
How do I fix FG-IR-26-163?
To fix FG-IR-26-163, update Apache HTTP Server to version 2.4.68 or higher.
3
What systems are affected by FG-IR-26-163?
FG-IR-26-163 affects Apache HTTP Server versions from 2.4.17 through 2.4.67.
4
What type of vulnerability is FG-IR-26-163?
FG-IR-26-163 is a Memory Allocation with Excessive Size Value vulnerability.
5
What is the impact of FG-IR-26-163?
The impact of FG-IR-26-163 can lead to denial of service via malicious HTTP requests.