logo

HTTP/2 Bomb Denial-of-Service Vulnerability

ID: d5cce598-0b6f-5550-9d9f-e8b6de8495ae

STIX ID: report--d5cce598-0b6f-5550-9d9f-e8b6de8495ae

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-07-28

...
...

Security researchers disclosed CVE-2026-49975, an HTTP/2 'HTTP/2 Bomb' denial-of-service technique that combines HPACK compression amplification and Slowloris-style connection holds to rapidly exhaust memory and processing resources on default HTTP/2 deployments; a public proof-of-concept exists and organizations are advised to patch and review HTTP/2 resource limits to prevent service outages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.