CVE-2026-49975
High · CVSS 7.5Apache HTTP Server (mod_http) — Memory Allocation with Excessive Size Value leading to Denial of Service (CWE-789, CWE-409)
- CVSS
- 7.5
- nvd
- EPSS
- 28.0%
- 98th pct
- KEV
- No
- Class
- kernel local
- CWE-789, CWE-409
Description
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Search profile — drives PoC discovery
Symbols mod_httpap_mallocapr_pallocap_rwritecontent-lengthexcessive allocationdeflatemod_deflater->remainingap_get_brigade
Keywords CVE-2026-49975Apache HTTP Servermod_httpdenial of servicememory allocationexcessive sizeCWE-789CWE-409httpd 2.4malicious HTTP requestoss-securityRHSA-2026:25042
Versions: 2.4.17 through 2.4.67
Ranked PoCs (12) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 13EQSTLab/CVE-2026-49975 candidatecontainerized · cited in references · recent activitygh_search · Python
- ★ 0
- ★ 0
- ★ 4
- ★ 2
- ★ 4
- ★ 2
- ★ 1
- ★ 1
- ★ 28mrx-arafat/CVE-2026-49975-POC needs reviewgh_search · Python
- ★ 6gh_search · Python
- ★ 2renzi25031469/CVE-2026-49975-HTTP-2-Bomb needs reviewgh_search · Shell
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://httpd.apache.org/security/vulnerabilities_24.html
- http://www.openwall.com/lists/oss-security/2026/06/03/3
- http://www.openwall.com/lists/oss-security/2026/06/08/16
- https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html
- https://access.redhat.com/errata/RHSA-2026:25042
- https://access.redhat.com/errata/RHSA-2026:25057
- https://access.redhat.com/errata/RHSA-2026:25090
- https://access.redhat.com/errata/RHSA-2026:25225
- https://access.redhat.com/errata/RHSA-2026:27114
- https://access.redhat.com/errata/RHSA-2026:27200
- https://access.redhat.com/errata/RHSA-2026:27201
- https://access.redhat.com/errata/RHSA-2026:36373
Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T18:30:14.000Z