CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

HTTP/2 Bomb CVE-2026-49975

unknownCVE-2026-49975
CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-12 00:00:00

CSIRTS triage

What
Memory allocation vulnerability in Apache HTTP Server mod_http enables denial of service via oversized HTTP/2 requests.
Who is affected
Apache HTTP Server instances between 2.4.17 and 2.4.67 processing HTTP/2 traffic.
Urgency
Moderate urgency; CVSS 5.8 causes service unavailability without code execution.
Action
Update Apache HTTP Server to 2.4.68 or later to patch CVE-2026-49975.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch HTTP Server

Get an email when a new HTTP Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
Fortinet FortiGuard PSIRT (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync

Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-163

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-49975coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Fortinet FortiGuard PSIRT