Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
[POC] CVE-2026-49975 — http2-bomb-analysis-paper
HTTP/2 Bomb: HPACK indexed-reference amplification + flow-control stall. A high school student's full protocol analysis (LaTeX). CVE-2026-49975, CVE-2026-47774.
[POC] CVE-2026-49975 — http2-bomb
CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console
[POC] CVE-2026-49975 — http2-bomb-detector
HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.
[POC] CVE-2026-49975 — Proof-of-Concept-POC---CVE-2026-49975-HTTP-2-Bomb-
Este repositorio contiene un Proof of Concept (POC) para CVE-2026-49975, también conocida como HTTP/2 Bomb, una vulnerabilidad de denegación de servicio (DoS) remoto que afecta a la mayoría de los servidores web principales en su configuración HTTP/2 predeterminada, incluyendo:
[POC] CVE-2026-49975 — http2-bomb
Proof of Concept (PoC) for CVE-2026-49975 – HTTP/2 server memory exhaustion attack leveraging HPACK amplification and connection retention (HTTP/2 Slowloris).
[POC] CVE-2026-49975 — CVE-2026-49975
HTTP2-Bomb
[POC] CVE-2026-49975 — CVE-2026-49975-HTTP-2-Bomb
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
[POC] CVE-2026-49975 — CVE-2026-49975-POC
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
[POC] CVE-2026-49975 — CVE-2026-49975
CVE-2026-49975漏洞复现
[POC] CVE-2026-49975 — http2-bomb-detector
HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.
PoC: CVE-2026-49975
HTTP2-Bomb
PoC: CVE-2026-49975
CVE-2026-49975
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free