Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4620-1 | apache2 security update |
Debian DSA |
DSA-6323-1 | apache2 security update |
Ubuntu USN |
USN-8398-1 | nginx vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 08 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible. | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. |
| Title | httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack | Apache HTTP Server: mod_http2 denial of service |
| Weaknesses | CWE-789 | |
| References |
|
Sat, 06 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible. | |
| Title | httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-08T22:32:35.729Z
Reserved: 2026-06-02T17:20:37.983Z
Link: CVE-2026-49975
No data.
Status : Received
Published: 2026-06-08T16:16:44.223
Modified: 2026-06-08T23:17:25.063
Link: CVE-2026-49975
OpenCVE Enrichment
Updated: 2026-06-08T17:45:16Z
Debian DLA
Debian DSA
Ubuntu USN