Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities FortiGuard Outbreak Alerts

HTTP/2 Bomb Denial-of-Service Vulnerability

  • What: New HTTP/2 DoS vulnerability disclosed
  • Impact: Servers using affected implementations may be vulnerable to resource exhaustion
Read Full Article →

Outbreak Alert HTTP/2 Bomb Denial-of-Service Vulnerability Released: Jun 19, 2026 Download PDF » Share HTTP2 Bomb DoS Vulnerability DoS Tags Medium Severity Microsoft IIS Server, Nginx web server, OpenSSL Platform Microsoft, Apache Vendor Share Subscribe Overview Analysis Solutions Threat Intelligence References Subscribe Overview Analysis Solutions Threat Intelligence References Enables Resource Exhaustion and Service Outages Security researchers have disclosed a new denial-of-service (DoS) attack technique dubbed HTTP/2 Bomb, tracked as CVE-2026-49975, that affects multiple major HTTP/2 server implementations. Unlike traditional volumetric DDoS attacks, HTTP/2 Bomb does not require a large botnet. Researchers demonstrated that a single attacker operating from a modest internet connection can generate sufficient resource exhaustion to disrupt vulnerable servers. Learn More » Common Vulnerabilities and Exposures CVE-2026-49975 Background The attack chains an HPACK compression amplification technique with a Slowloris-style connection hold to rapidly consume server memory and processing resources, causing service outages within seconds. Public proof-of-concept (PoC) code is available. This vulnerability targets the HTTP/2 protocol layer itself, which is widely enabled across internet-facing websites, APIs, cloud applications, reverse proxies, load balancers, and web services. The attack affects default HTTP/2 configurations in several of the world's most commonly deployed web server platforms. Because exploitation results in loss of service availability rather than code execution, organizations may underestimate the risk. However, for customer-facing applications, SaaS platforms, financial services, e-commerce sites, and critical infrastructure portals, successful exploitation can lead to significant business disruption. Click here to analyze the Real-Time Threat Map Latest Development Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered. While the vulnerability does not enable system compromise, the breadth of HTTP/2 adoption across internet-facing infrastructure creates a substantial attack surface. Organizations operating publicly accessible web applications should prioritize patching affected HTTP/2 implementations and review HTTP/2-specific resource limits and rate controls. June 16, 2026: Apache releases fixes for affected implementations. June 03, 2026: Public PoC becomes available June 02, 2026: Public disclosure of HTTP/2 Bomb and CVE-2026-49975 https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb FortiGuard Cybersecurity Framework Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services. PROTECT IPS DETECT IOC Outbreak Detection RESPOND Automated Response Assisted Response Services RECOVER NOC/SOC Training End-User Training IDENTIFY Attack Surface Hardening IPS Detects and blocks attack attempts leveraging the vulnerability FortiADC DB 36.234 FortiGate DB 36.234 FortiNDR DB 36.234 FortiNDR Cloud DB 36.234 FortiProxy DB 36.234 FortiSASE DB 36.234 IOC FortiAnalyzer FortiCloud SOCaaS FortiSIEM FortiSOAR Outbreak Detection FortiAnalyzer Automated Response Services that can automaticlly respond to this outbreak. FortiXDR Assisted Response Services Experts to assist you with analysis, containment and response activities. Incident Response NOC/SOC Training Train your network and security professionals and optimize your incident response to stay on top of the cyberattacks. NSE Training Response Readiness End-User Training Raise security awareness to your employees that are continuously being targeted by phishing, drive-by download and other forms of cyberattacks. Security Awareness & Training Attack Surface Hardening Check Security Fabric devices to build actionable configuration recommendations and key indicators. Security Rating Threat Intelligence Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities. ✖ References Sources of information in support and relation to this Outbreak and vendor. OSS Security Learn More » Apache Learn More » Debian LTS Advisory Learn More » About FortiGuard Outbreak Alerts Learn More »

Share this article