All findings

CVE-2026-49975 medium

Codex-assisted HTTP/2 Bomb reaches Apache and other major servers

Calif used OpenAI Codex to identify a denial-of-service technique affecting major HTTP/2 implementations; Apache assigned CVE-2026-49975 to its mod_http2 variant.

Bug class
HTTP/2 denial of service through decompression work amplification
Affected codebase
Apache HTTP Server and HTTP/2 server implementations
Credited system
OpenAI Aardvark / Codex Security
Also credited
OpenAI Daybreak
Disclosed
June 22, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Apache directly credits Quang Luong of Calif.io in collaboration with OpenAI Codex on CVE-2026-49975. Calif and OpenAI document the broader HTTP/2 Bomb technique and coordinated fixes across server implementations.

Summary

The HTTP/2 Bomb technique uses a small compressed header block to trigger disproportionate server work. Calif reports affected implementations across NGINX, Apache, IIS, Envoy, and Pingora. Apache’s public identifier is CVE-2026-49975, a Moderate mod_http2 denial of service fixed in 2.4.68.

Counting boundary

Bugflation counts the public Apache CVE and records the multi-server context. It does not manufacture additional CVEs for implementation fixes that have no public identifier or distinct advisory.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.