HTTP/2 VULNERABILITY

impeeza

¡Kabito!
Member
Joined
Apr 5, 2011
Messages
10,552
Solutions
3
Reaction score
31,466
Trophies
6
Age
48
Location
At my chair.
XP
39,892
Country
Colombia
Fellow tempers be aware of a new vulnerability affecting almost all webservers, the CVE-2026-49975 (reserved link) is a remote denial‑of‑service vulnerability known as the “HTTP/2 Bomb,” which exploits how HTTP/2 handles header compression and connection flow control to force servers to allocate and retain excessive memory from very small requests. By combining HPACK compression amplification with stalled connections, an attacker can exhaust tens of gigabytes of memory in seconds using minimal bandwidth, making systems unresponsive.

In short, this exploit enables low-cost, high-impact denial-of-service conditions against exposed HTTP/2 services.

Platform(s) and Version(s) Affected:

Platform(s)Vulnerable Version(s)Patched Stable Version(s)
Nginx<1.29.81.30.2
Apache httpdAll HTTP/2-enabled buildsFix is provided at the module level
Microsoft IISAll HTTP/2-enabled buildsFix is not yet available
Envoy Proxy<1.39Envoy Advisory
Cloudflare PingoraNo official announcementFix not yet available

Active Exploits:

There is no evidence that the vulnerability has been actively exploited in the wild. However, public proof-of-concept (PoC) code and technical details are available, lowering the barrier for potential exploitation and increasing the likelihood of rapid weaponization.

References:

 
Last edited by impeeza,
  • Like
Reactions: SylverReZ

Site & Scene News

Popular threads in this forum