CVE-2026-49975

Published Jun 8, 2026

Last updated 24 days ago

CVSS high 7.5
Openresty
Tunneling protocol
Server
Port (443)
HTTP

Overview

Description
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Source
security@apache.org
NVD status
Modified
Products
http_server, debian_linux

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security@apache.org
CWE-789
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-409

Social media

Hype score
Not currently trending
  1. 8 Apache HTTP Server CVEs patched in Debian 13.6 🚨 🔵 CVE-2026-29167 – mod_ldap UAF (CVSS ~9.8) 🔵 CVE-2026-48913 – mod_http2 UAF (7.3) 🔵 CVE-2026-34355/34356/42536 – buffer overflows 🔵 CVE-2026-29170 – mod_proxy_ftp XSS 🔵 CVE-2026-49975/44186 – DoS Up

    @techepages

    13 Jul 2026

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-49975. 0day Intel: ⚠️CVE-2026-49975 (CVSS 7.5)⚠️ Critical HTTP/2 Bomb Denial-of-Service vulnerabili

    @lyrie_ai

    12 Jul 2026

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. After analyzing 60% of vulnerabilities from past week, CVE-2026-49975 has 77 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    @stooee_

    26 Jun 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. After analyzing 60% of vulnerabilities from past week, CVE-2026-49975 has 77 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    @stooee_

    25 Jun 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. After analyzing 51% of vulnerabilities from past week, CVE-2026-49975 has 77 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    @stooee_

    20 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. SIOSセキュリティブログを更新しました。 Apacheの脆弱性(Moderate: CVE-2026-34355, CVE-2026-42535, CVE-2026-43951, CVE-2026-44119, CVE-2026-44186, CVE-2026-49975, Low:複数)と2.4.68リリース #sios_tech #security #vulnerability #セキュリティ #脆弱

    @omokazuki

    9 Jun 2026

    126 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. #threatreport #LowCompleteness Codex Discovered a Hidden HTTP/2 Bomb | 03-06-2026 Source: https://t.co/iJtoMISHg7 Key details below ↓ 💀Threats: Slowloris_technique, 🎯Victims: Web servers, Apache httpd, Envoy, Nginx, Iis, Pingora 🏭Industry: Transport 🔓CVEs: CVE-2

    @rst_cloud

    8 Jun 2026

    234 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Top 5 Trending CVEs: 1 - CVE-2018-17144 2 - CVE-2026-46243 3 - CVE-2026-49975 4 - CVE-2025-49113 5 - CVE-2026-28318 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    7 Jun 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. SBが出たってことはアップデートはまだ時間かかりそうですかね... // RHSB-2026-007 HTTP/2 HPACK Denial of Service - httpd, nginx, Envoy (CVE-2026-49975, CVE-2026-47774) - "HTTP/2 Bomb" | Red Hat Customer Portal https://t.co/rTVi57F2Xq

    @w4yh

    7 Jun 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【主観的_最新のインシデント傾向】 レンタルサーバーのサービスも攻撃されています ログの種類やバックアップ手順は業者任せにせず確認しましょう ・NGINX/Apache HTTP/2 Bomb (CVE-2026-49975) ・cPanel/WHM (CVE-2026-4194

    @shunyat1031

    6 Jun 2026

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Slackware 15.0 released fixed net-tools and httpd packages addressing CVE-2026-154 stack-based buffer overflow and CVE-2026-49975 HTTP/2 DoS "HTTP/2 Bomb", Linuxsecurity reported. https://t.co/mKFtz5UhJr

    @threatcluster

    4 Jun 2026

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-53020 (Moderate: 5.3) でmod_http2のアップデートが来ていますがこれですかね? < CVE-2026-49975 // CVE-2025-53020 https://t.co/Mi7Jo3wIp8

    @w4yh

    4 Jun 2026

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations

  1. Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated the anti-replay counter too late. After AEAD decryption of a MESSAGE_TRANSPORT_DATA packet succeeded, the code committed several peer-state changes — update_peer_addr() (endpoint roaming update), the keypair->last_rx/peer->last_rx liveness timers, and keypair_update() (promote next→current and destroy the previous keypair) — and only afterward called wg_check_replay(). On a replayed packet the replay check returned -EINVAL, but none of the preceding mutations were rolled back. The AEAD tag authenticates content but not freshness, so a replayed-but-authentic transport packet decrypts correctly. An attacker who captures one valid ciphertext off the wire (an on-path or shared-medium observer) can re-inject it from an arbitrary spoofed source address. Reaching the handler requires no credentials: it is driven directly from inbound UDP datagrams via the dispatch in subsys/net/lib/wireguard/wg.c. Because the state mutations committed before the replay check, the replay repoints the peer endpoint to the attacker-chosen source address (roaming hijack), redirecting the victim's subsequent outbound tunnel traffic until the legitimate peer's next packet re-corrects it; it also prematurely destroys the previous keypair and refreshes the RX liveness timer. The tunnel payload stays encrypted under the session keypair, so this is an integrity/availability impact (traffic redirection and session disruption), not payload disclosure. The fix moves wg_check_replay() to immediately after a successful decrypt, before any peer-state mutation, matching the WireGuard specification and the Linux reference implementation.CVE-2026-13734