CVE-2026-49975
CVE-2026-49975: 4 tracked advisory records across Apache, Fortinet, NetApp and 1 more. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityUnrated
Advisory [CVE-2026-49975] Apache HTTP Server: mod_http2 denial of service
CVE-2026-49975Source published Source updated
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
- Affected products in this advisory
- Apache HTTP Server
- Source-reported affected versions
- Apache HTTP Server 2.4.17 through 2.4.67
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Fortinet
1 advisory- Advisory severityMedium5.8
Medium [CVE-2026-49975] HTTP/2 Bomb CVE-2026-49975
FG-IR-26-163Source published Source updated
CVSSv3 Score: 5.8 CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-19 00:00:00
- Affected products in this advisory
- FortiPAM
- FortiProxy
- FortiSwitchManager
- Source-reported affected versions
- 2.4.17
- 2.4.67
- Source-reported fixed versions
- FortiPAM 1.9: 1.9.2
- FortiPAM 1.8: migrate to a fixed release
- FortiPAM 1.7: migrate to a fixed release
- FortiPAM 1.6: migrate to a fixed release
10 more entries in the full advisory.
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiPAM 1.9: 1.9.2; FortiPAM 1.8: migrate to a fixed release; FortiPAM 1.7: migrate to a fixed release; FortiPAM 1.6: migrate to a fixed release; FortiPAM 1.5: migrate to a fixed release; ….
NetApp
1 advisory- Advisory severityHigh8.7
High [CVE-2026-49975] Apache HTTP Server Vulnerability in NetApp Products
NTAP-20260610-0003Source published Source updated
The default HTTP/2 protocol configuration in certain web servers, such as Apache HTTP Server, allows a remote Denial of Service (DoS). This vulnerability is known as HTTP/2 Bomb. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- Management Services for Element Software and NetApp HCI
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-49975] Remote Denial of Service via compression bomb and Slowloris-style attack
CVE-2026-49975Source published
Remote Denial of Service via compression bomb and Slowloris-style attack. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): jbcs-httpd24-httpd, mod_http2, jbcs-httpd24-mod_http2, httpd-main, httpd:2.4, openshift-service-mesh/proxyv2-rhel9:1781604724. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`).
- Affected products in this advisory
- JBoss Core Services for RHEL 8
- JBoss Core Services on RHEL 7
- Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
11 more entries in the full advisory.
- Source-reported affected versions
- jbcs-httpd24-httpd
- jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs
- mod_http2-0:2.0.26-6.el9_8.1
- jbcs-httpd24-mod_http2
7 more entries in the full advisory.
- Source-reported fixed versions
- RHSA-2026:27200
- Mitigation guidance
- Update the affected package(s) to the fixed version shipped in RHSA-2026:27200 (`sudo dnf update` / `yum update`).
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.