Bug 2485371 (CVE-2026-49975)

Summary: CVE-2026-49975 httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: alexander_pircher, cchiang, csutherl, dsoumis, jclere, jwon, kaycoth, kevinxue, pjindal, plodge, rhel-process-autobot, rmaucher, szappis, vchlup, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2485396, 2485558, 2485394, 2485395    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-05 06:09:18 UTC
We’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, including:

nginx

Apache httpd

Microsoft IIS

Envoy

Cloudflare Pingora

The vulnerable behavior exists in each server's default HTTP/2 configuration.

The attack was discovered by Codex, which chained two techniques known to humans for a decade: a compression bomb and a Slowloris-style hold. The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.

A curious search on Shodan revealed 880,000+ websites supporting HTTP/2 and running one of these servers, though many sit behind a CDN, which is much harder to bring down.

A home computer on a 100Mbps connection can render a vulnerable server inaccessible within seconds. Against Apache httpd and Envoy, a single client can consume and hold 32GB of server memory in roughly 20 seconds.

Comment 4 errata-xmlrpc 2026-06-10 11:15:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:25057 https://access.redhat.com/errata/RHSA-2026:25057

Comment 5 errata-xmlrpc 2026-06-10 16:36:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:25090 https://access.redhat.com/errata/RHSA-2026:25090

Comment 6 errata-xmlrpc 2026-06-11 10:32:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:25225 https://access.redhat.com/errata/RHSA-2026:25225

Comment 8 errata-xmlrpc 2026-06-22 15:13:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP4

Via RHSA-2026:27201 https://access.redhat.com/errata/RHSA-2026:27201

Comment 9 errata-xmlrpc 2026-06-22 15:15:26 UTC
This issue has been addressed in the following products:

  JBoss Core Services on RHEL 7
  JBoss Core Services for RHEL 8

Via RHSA-2026:27200 https://access.redhat.com/errata/RHSA-2026:27200

Comment 10 Alex Pircher 2026-06-30 15:06:52 UTC
Errata for nginx is missing.

Comment 11 errata-xmlrpc 2026-07-07 21:41:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:36373 https://access.redhat.com/errata/RHSA-2026:36373

Comment 12 errata-xmlrpc 2026-07-08 17:54:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:36831 https://access.redhat.com/errata/RHSA-2026:36831

Comment 13 errata-xmlrpc 2026-07-08 19:29:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:36846 https://access.redhat.com/errata/RHSA-2026:36846