HIGH

CVE-2026-49975

Apache HTTP Server: mod_http2 denial of service

CVSS v3

7.5

HIGH

EPSS Score

10.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published
6/19/2026
Last Modified
8/19/2026
MSRC Title
Apache HTTP Server: mod_http2 denial of service

Frequently asked questions

What is CVE-2026-49975?

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Is CVE-2026-49975 actively exploited?

A proof-of-concept exploit exists for CVE-2026-49975, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-49975?

CVE-2026-49975 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Is CVE-2026-49975 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.