HTTP/2 Bomb CVE-2026-49975
CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-12 00:00:00
CSIRTS triage
- What
- Memory allocation vulnerability in Apache HTTP Server mod_http enables denial of service via oversized HTTP/2 requests.
- Who is affected
- Apache HTTP Server instances between 2.4.17 and 2.4.67 processing HTTP/2 traffic.
- Urgency
- Moderate urgency; CVSS 5.8 causes service unavailability without code execution.
- Action
- Update Apache HTTP Server to 2.4.68 or later to patch CVE-2026-49975.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch HTTP Server
Get an email when a new HTTP Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-163
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2026-4997528.0% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49975 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] HTTP/2 implementations: Vulnerability allows denial of servicecert-bund
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- unknownZimbra Denial of Service Vulnerabilityhkcert
- highCVE-2026-49975: Apache HTTP Server: mod_http2 denial of servicemsrc
More from Fortinet FortiGuard PSIRT
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownFGFM Authentication Weakening via CLI Configuration2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownStack buffer overflow in WAD2026-08-12
- unknownServer-Side Request Forgery (SSRF)2026-08-12