CVE-2026-49975: HTTP/2 Bomb: Remote DoS against most major web servers

Last Updated: 2026-06-03T21:27:00Z

What’s Happening

Another model-discovered vulnerability can shut down most HTTP servers, including Nginx and Apache.

Proofs of concept available on GitHub.

Actions

Apply available patches:

Server Vulnerable? Patched Version(s)
Nginx Yes 1.29.8
Apache Yes Fixed in mod_http2 v2.0.41
Envoy Yes 1.35.11, 1.36.7, 1.37.3, 1.38.1
IIS Yes Unknown
Cloudflare Pingora Yes Unknown
Caddy Unknown Unknown

Mitigate:

Cap per-worker memory (cgroups, ulimit -v, container limit, etc.)
(Also recommended generally for defense in depth / future vulnerabilities)

Notes

Envoy has patched.

Wow, nothing yet from common WAF providers:

https://www.akamai.com/blog

https://developers.cloudflare.com/changelog/product/waf/

https://my.f5.com/manage/s/global-search/

https://aws.amazon.com/security/security-bulletins/

And the Tenable Plugin ID:

https://www.tenable.com/plugins/nessus/318375

1 Like