https://seclists.org/oss-sec/2026/q2/845: CVE-2026-49975: Apache HTTP Server: mod_http2 denial of service
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Apache HTTP Server>=2.4.17<=2.4.67
Frequently Asked Questions
1
What is the severity of CVE-2026-49975?
CVE-2026-49975 has a moderate severity level.
2
What versions of Apache HTTP Server are affected by CVE-2026-49975?
CVE-2026-49975 affects Apache HTTP Server versions 2.4.17 through 2.4.67.
3
How does CVE-2026-49975 affect Apache HTTP Server?
CVE-2026-49975 leads to a denial of service due to memory allocation issues with excessive size values.
4
How can I mitigate CVE-2026-49975?
Mitigation for CVE-2026-49975 involves upgrading your Apache HTTP Server to a version later than 2.4.67.
5
What is the nature of the vulnerability in CVE-2026-49975?
The vulnerability in CVE-2026-49975 is related to memory allocation with excessive size values within the mod_http2 module.