<Vulnerability name="CVE-2026-49975">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-03T00:00:00</PublicDate>
    <Bugzilla id="2485371" url="https://bugzilla.redhat.com/show_bug.cgi?id=2485371" xml:lang="en:us">
httpd: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-409</CWE>
    <Details xml:lang="en:us" source="Mitre">
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.

This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible.
    </Details>
    <Statement xml:lang="en:us">
The Apache's `httpd` HTTP/2 protocol implementation has a denial-of-service (DoS) vulnerability that is rated as Important. An unauthenticated remote attacker can exploit this flaw by combining HPACK compression with flow control manipulation, leading to significant server memory exhaustion and rendering the service inaccessible. This vulnerability exists in default HTTP/2 configurations.
    </Statement>
    <Mitigation xml:lang="en:us">
See the security bulletin for a detailed mitigation procedure.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_core_services:1::el8">
        <ProductName>JBoss Core Services for RHEL 8</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27200">RHSA-2026:27200</Advisory>
        <Package name="jbcs-httpd24-httpd">jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_core_services:1::el8">
        <ProductName>JBoss Core Services for RHEL 8</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27200">RHSA-2026:27200</Advisory>
        <Package name="jbcs-httpd24-mod_http2">jbcs-httpd24-mod_http2-0:2.0.29-10.el8jbcs</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_core_services:1::el7">
        <ProductName>JBoss Core Services on RHEL 7</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27200">RHSA-2026:27200</Advisory>
        <Package name="jbcs-httpd24-httpd">jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_core_services:1::el7">
        <ProductName>JBoss Core Services on RHEL 7</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27200">RHSA-2026:27200</Advisory>
        <Package name="jbcs-httpd24-mod_http2">jbcs-httpd24-mod_http2-0:2.0.29-10.el7jbcs</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25225">RHSA-2026:25225</Advisory>
        <Package name="mod_http2">mod_http2-0:2.0.29-4.el10_2.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25090">RHSA-2026:25090</Advisory>
        <Package name="httpd:2.4">httpd:2.4-8100020260608081321.489197e6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25057">RHSA-2026:25057</Advisory>
        <Package name="mod_http2">mod_http2-0:2.0.26-6.el9_8.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services 2.4.62.SP4</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27201">RHSA-2026:27201</Advisory>
        <Package name="jbcs-httpd24-httpd">jbcs-httpd24-httpd</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services 2.4.62.SP4</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27201">RHSA-2026:27201</Advisory>
        <Package name="jbcs-httpd24-mod_http2">jbcs-httpd24-mod_http2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25042">RHSA-2026:25042</Advisory>
        <Package name="httpd-main">httpd-main-2.4.68-1.hum1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:service_mesh:2.6::el9">
        <ProductName>Red Hat OpenShift Service Mesh 2.6</ProductName>
        <ReleaseDate>2026-06-18T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:27114">RHSA-2026:27114</Advisory>
        <Package name="openshift-service-mesh/proxyv2-rhel9">openshift-service-mesh/proxyv2-rhel9:1781604724</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-apache-commons-daemon</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-apache-commons-daemon-jsvc</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-apr</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-apr-util</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-brotli</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-compose</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-curl</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-dist</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-jansson</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-mod_cluster-native</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-mod_jk</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-mod_md</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-mod_proxy_cluster</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-mod_security</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-nghttp2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-openssl</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-openssl-chil</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-openssl-pkcs11</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:5">
        <ProductName>Red Hat JBoss Web Server 5</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-apr</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:5">
        <ProductName>Red Hat JBoss Web Server 5</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-openssl</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-49975
https://nvd.nist.gov/vuln/detail/CVE-2026-49975
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
    </References>
</Vulnerability>