Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49975

Опубликовано: 03 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible.

Отчет

The Apache's httpd HTTP/2 protocol implementation has a denial-of-service (DoS) vulnerability that is rated as Important. An unauthenticated remote attacker can exploit this flaw by combining HPACK compression with flow control manipulation, leading to significant server memory exhaustion and rendering the service inaccessible. This vulnerability exists in default HTTP/2 configurations.

Меры по смягчению последствий

See the security bulletin for a detailed mitigation procedure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Core Servicesjbcs-httpd24-apache-commons-daemonNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-apache-commons-daemon-jsvcNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-aprNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-apr-utilNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-brotliNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-composeNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-curlNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-distNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-janssonNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-mod_cluster-nativeNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2485371httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack

EPSS

Процентиль: 97%
0.16833
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

CVSS3: 7.5
nvd
около 2 месяцев назад

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

CVSS3: 7.5
msrc
около 2 месяцев назад

Apache HTTP Server: mod_http2 denial of service

CVSS3: 7.5
debian
около 2 месяцев назад

Memory Allocation with Excessive Size Value vulnerability in Apache HT ...

rocky
около 2 месяцев назад

Important: mod_http2 security update

EPSS

Процентиль: 97%
0.16833
Средний

7.5 High

CVSS3