PT-2026-45945 · Microsoft+8 · Iis+8

·

CVE-2026-49975

·

Published

2026-05-27

·

Updated

2026-08-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.17 through 2.4.67 nginx (affected versions not specified)
Description A flaw in the HTTP/2 implementation allows a remote attacker to cause a denial of service (DoS) by inducing excessive memory allocation. The attack, dubbed the HTTP/2 Bomb, combines HPACK compression amplification with flow-control stalling. An attacker can insert a header into the HPACK dynamic table and reference it repeatedly using a compact indexed representation, creating a loop that requires increasing memory. Simultaneously, the attacker uses a zero-byte flow-control window to prevent the server from freeing this memory, periodically sending WINDOW UPDATE frames to avoid timeouts. This allows a single low-bandwidth connection to exhaust server memory rapidly, rendering the server inaccessible. In Apache HTTP Server, this issue specifically affects the mod http and mod http2 modules. In nginx, the issue relates to the incorrect handling of certain cookie headers in the HTTP/2 implementation.
Recommendations Update Apache HTTP Server to version 2.4.68 or later. Update nginx to the following package versions: libnginx-mod-http-auth-pam - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-cache-purge - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-dav-ext - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-echo - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-fancyindex - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-geoip - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-geoip2 - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-headers-more-filter - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-image-filter - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-lua - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-ndk - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-perl - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-subs-filter - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-uploadprogress - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-upstream-fair - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-xslt-filter - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-mail - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-nchan - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-rtmp - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-stream - 1.18.0-0ubuntu1.7+esm3, nginx - 1.18.0-0ubuntu1.7+esm3, nginx-common - 1.18.0-0ubuntu1.7+esm3, nginx-core - 1.18.0-0ubuntu1.7+esm3, nginx-doc - 1.18.0-0ubuntu1.7+esm3, nginx-extras - 1.18.0-0ubuntu1.7+esm3, nginx-full - 1.18.0-0ubuntu1.7+esm3, nginx-light - 1.18.0-0ubuntu1.7+esm3, libnginx-mod-http-geoip - 1.24.0-2ubuntu7.12, libnginx-mod-http-image-filter - 1.24.0-2ubuntu7.12, libnginx-mod-http-perl - 1.24.0-2ubuntu7.12, libnginx-mod-http-xslt-filter - 1.24.0-2ubuntu7.12, libnginx-mod-mail - 1.24.0-2ubuntu7.12, libnginx-mod-stream - 1.24.0-2ubuntu7.12, libnginx-mod-stream-geoip - 1.24.0-2ubuntu7.12, nginx - 1.24.0-2ubuntu7.12, nginx-common - 1.24.0-2ubuntu7.12, nginx-core - 1.24.0-2ubuntu7.12, nginx-dev - 1.24.0-2ubuntu7.12, nginx-doc - 1.24.0-2ubuntu7.12, nginx-extras - 1.24.0-2ubuntu7.12, nginx-full - 1.24.0-2ubuntu7.12, nginx-light - 1.24.0-2ubuntu7.12. As a temporary mitigation, disable HTTP/2 or use a reverse proxy/CDN to enforce hard header-count limits.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25057
ALSA-2026:25090
ALSA-2026:25225
AZL-89510
AZL-89550
AZL-89760
BDU:2026-07789
BIT-APACHE-2026-49975
CVE-2026-49975
ECHO-C67B-44B0-FF31
OESA-2026-2611
OESA-2026-2627
OESA-2026-2638
OESA-2026-2639
OESA-2026-2640
OPENSUSE-SU-2026:21235-1
RHSA-2026:25042
RHSA-2026:25057
RHSA-2026:25090
RHSA-2026:25225
RHSA-2026:27200
SUSE-SU-2026:22564-1
SUSE-SU-2026:2686-1
SUSE-SU-2026:2717-1
SUSE-SU-2026:2735-1
SUSE-SU-2026:2759-1
USN-8384-1
USN-8398-1
USN-8398-2
USN-8398-3
USN-8398-4
USN-8571-1

Affected Products

Apache Http Server
Envoy
Iis
Linuxmint
Pingora
Red Os
Rocky Linux
Ubuntu
Nginx