HTTP/2 Bomb Denial-of-Service Vulnerability
ID: d5cce598-0b6f-5550-9d9f-e8b6de8495ae
STIX ID: report--d5cce598-0b6f-5550-9d9f-e8b6de8495ae
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
Threat Score
Security researchers disclosed CVE-2026-49975, an HTTP/2 'HTTP/2 Bomb' denial-of-service technique that combines HPACK compression amplification and Slowloris-style connection holds to rapidly exhaust memory and processing resources on default HTTP/2 deployments; a public proof-of-concept exists and organizations are advised to patch and review HTTP/2 resource limits to prevent service outages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
