Feed/CVE-2026-4997
CVE-2026-4997MEDIUMCVSS 5.3

CVE-2026-4997

Published Mar 28, 2026·Updated Jun 17, 2026

NVD Description

A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Public Exploits & PoCs10 found

[POC] CVE-2026-49975 — http2-bomb-analysis-paper

HTTP/2 Bomb: HPACK indexed-reference amplification + flow-control stall. A high school student's full protocol analysis (LaTeX). CVE-2026-49975, CVE-2026-47774.

1

[POC] CVE-2026-49975 — http2-bomb

CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console

1

[POC] CVE-2026-49975 — http2-bomb-detector

HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.

1

[POC] CVE-2026-49975 — Proof-of-Concept-POC---CVE-2026-49975-HTTP-2-Bomb-

Este repositorio contiene un Proof of Concept (POC) para CVE-2026-49975, también conocida como HTTP/2 Bomb, una vulnerabilidad de denegación de servicio (DoS) remoto que afecta a la mayoría de los servidores web principales en su configuración HTTP/2 predeterminada, incluyendo:

1

[POC] CVE-2026-49975 — http2-bomb

Proof of Concept (PoC) for CVE-2026-49975 – HTTP/2 server memory exhaustion attack leveraging HPACK amplification and connection retention (HTTP/2 Slowloris).

[POC] CVE-2026-49975 — CVE-2026-49975

HTTP2-Bomb

[POC] CVE-2026-49975 — CVE-2026-49975-HTTP-2-Bomb

Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.

[POC] CVE-2026-49975 — CVE-2026-49975-POC

HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)

[POC] CVE-2026-49975 — CVE-2026-49975

CVE-2026-49975漏洞复现

[POC] CVE-2026-49975 — http2-bomb-detector

HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free