CVE-2026-49975
📛 CVE Title
Apache HTTP Server: mod_http2 denial of service
Description
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.5 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Effective score
- 7.5 / 10 HIGH source: CNA overview
- MSRC score
- 7.5 / 10 HIGH MS rating: Important
- CWE(s)
-
CWE-789 - Reserved
- —
- Published
- 2026-06-09 07:00 UTC
- Last updated
- 2026-06-20 01:43 UTC
- Source
- https://www.tenable.com/cve/CVE-2026-49975
- Linked Threat
- CVE-2026-49975 — CVE-2026-49975
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-08 16:16:44 UTC
- NVD last modified
- 2026-07-23 07:10:00 UTC
- NVD CVSS v3.1
- 7.5 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.2798 (probability of exploitation in next 30 days)
- EPSS percentile
- 97.91% vs all CVEs — higher = more likely to be exploited, as of 2026-08-01
NVD-assigned CWE(s):
CWE-789,
CWE-409
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-08-01 16:30 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-35105 - Assigner
- apache
- Published
- Jun 8, 2026, 3:26:04 PM
- Updated
- Jul 15, 2026, 12:47:26 AM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EUVD-reported EPSS
- 27.9800
- Vendors
- Apache Software Foundation
- Products
-
Apache HTTP Server (2.4.17 ≤2.4.67)
- Aliases
-
GHSA-262v-g5h9-6mc6
ENISA description: Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-23 03:00 UTC (source: CVRF).
- MS severity
- Important
- MS CVSS base score
- 7.5 / 10 (temporal 7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Release
- 2026-Jun
Microsoft remediations / KB articles (2)
- CBL-Mariner Releases — Vendor Fix / Security Update (fixed build 1.28.3-5)
- https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade — None Available / CBL-Mariner Releases
Affected products — CPE 2.3 (2) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (11)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- MSRC update guide: CVE-2026-49975 msrc
- https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb tenable:blog.calif.io
- https://httpd.apache.org/security/vulnerabilities_24.html tenable:httpd.apache.org
- https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html tenable:lists.debian.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-49975 tenable:nvd.nist.gov
- https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/ tenable:www.bleepingcomputer.com
- https://www.cve.org/CVERecord?id=CVE-2026-49975 tenable:www.cve.org
- http://www.openwall.com/lists/oss-security/2026/06/03/3 tenable:www.openwall.com
- https://www.theregister.com/security/2026/06/04/openais-codex-chains-decade-old-dos-techniques-into-http/2-bomb/5251377 tenable:www.theregister.com
- http://www.openwall.com/lists/oss-security/2026/06/08/16 tenable:www.openwall.com
NVD-tagged references (18)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- http://www.openwall.com/lists/oss-security/2026/06/03/3 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/06/08/16 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://github.com/EQSTLab/CVE-2026-49975 134c704f-9b21-4f2e-91b3-4a467353bcc0 ExploitThird Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html security@apache.org Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:25042 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:25057 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:25090 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:25225 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:27114 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:27200 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:27201 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:36373 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:36831 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:36846 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/security/cve/CVE-2026-49975 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://bugzilla.redhat.com/show_bug.cgi?id=2485371 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49975.json 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybersecuritynews.com
BitLocker bypass enables attackers with physical access to defeat disk encryption and access protected data on Windows systems.
2026-06-19 02:37 UTC -
web:en-forum.guildwars2.com
05/12/2026—May 12 Release Notes Note to users of third-party programs: The game may not launch or work properly after we release a new build if you use a third-party program, due to possible incompatibilities. ArenaNet cannot offer support if a third-party modification breaks, interferes with, or ...
2026-06-19 02:37 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:37 UTC -
web:news.sportslogos.net
The Saints previously wore a patch celebrating their 25th season in 1991, 30th season in 1996 and 50th season in 2016.
2026-06-19 02:37 UTC -
web:windload.solutions
South Carolina Building Code Overview. South Carolina has adopted the 2021 South Carolina Building Code, which is based on the 2015 International Building Code (IBC) with state-sp
2026-06-19 02:37 UTC -
web:www.arkenopticsusa.com
FLAGSHIP STANDARD As Arken's iconic flagship, the EP-5 (Extreme Precision) combines Japanese ED/XED glass with a 56 mm objective for unmatched long-range clarity. Forged with our time-tested Arken Zero Stop and illuminated FFP VPR/TOR reticle, it delivers the precision and reliability serious shooters demand.
2026-06-19 02:37 UTC -
web:www.beaconjournal.com
Dr. Marc Harrison is stepping down as CEO of Health Assurance Transformation Company on July 31, ahead of the company's purchase of Summa Health.
2026-06-19 02:37 UTC -
web:www.espn.com
After circling each other for years, Victor Wembanyama and Chet Holmgren will be judged heavily in the way they perform head-to-head throughout their professional careers.
2026-06-19 02:37 UTC -
web:www.nintendolife.com
Light 'em up - When the Switch launched, its new Joy-Con controllers were dreamy little wonders stuffed with neat tech and surprises. Unfortunately, the big...
2026-06-19 02:37 UTC -
web:www.patioproducts.com
45 vinyl strap colors of vinyl strapping for outdoor patio furniture. Straps pre-cut to size, by the foot, by the roll or by the pallet.
2026-06-19 02:37 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.