Summary
The HTTP/2 Bomb technique uses a small compressed header block to trigger
disproportionate server work. Calif reports affected implementations across
NGINX, Apache, IIS, Envoy, and Pingora. Apache’s public identifier is
CVE-2026-49975, a Moderate mod_http2 denial of service fixed in 2.4.68.
Counting boundary
Bugflation counts the public Apache CVE and records the multi-server context. It does not manufacture additional CVEs for implementation fixes that have no public identifier or distinct advisory.
References
- Apache HTTP Server 2.4 vulnerabilities
- Calif: Codex discovered a hidden HTTP/2 Bomb
- OpenAI: Patch the Planet
- CVE record: CVE-2026-49975
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.