CVE-2026-49975
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
- Affected products
- Apache Http Server, Envoy, Iis, Linuxmint, Pingora, Red Os, Rocky Linux, Ubuntu
- Apache Http Server
- < 2.4.68
- Debian Debian Linux
- = 11.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 31.0% (98th percentile)
- Weakness
- CWE-409, CWE-789
- NVD status
- Modified
- Published
- 2026-06-08
CVE-2026-49975 at NVD
20 known exploits for CVE-2026-49975
Proof-of-concept code and exploit modules indexed by Sploitus
http2-bomb-detector
http2-bomb
CVE-2026-49975
CVE-2026-49975
CVE-2026-49975
CVE-2026-49975-HTTP-2-Bomb
cve-2026-49975-http2bomb_reproduction
http2-bomb
CVE-2026-49975-POC
Proof-of-Concept-POC---CVE-2026-49975-HTTP-2-Bomb-
CVE-2026-49975
http2-bomb-analysis-paper
Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server
Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server
Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server
Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server
Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server
Exploit for Memory Allocation with Excessive Size Value in Apache Http_Server
Exploit for CVE-2026-49975
Exploit for CVE-2026-49975