Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/naheeju/poc-cve-2026-49975
Vulnerability AnalysisExploitationWeb SecurityNetwork Security
GitHubnaheeju/poc-cve-2026-49975

POC-CVE-2026-49975

Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2

View Repository
32620 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Go Version Status Scope CVSS License

CVE-2026-49975

HTTP/2 Bomb — HPACK Compression Bomb + Flow-Control Hold PoC

Security Research PoC by naheeju


⚠️ This is a working, memory-exhaustion DoS tool — not a toy. It opens streams that force the target to allocate memory and holds them open via HTTP/2 flow-control tricks. As long as the process is running, it keeps holding and automatically reconnects if the server drops the connection — it does not stop on its own. Impact scales directly with --threads, --streams, and --headers. Stopping the process (Ctrl+C) releases the held streams and lets the server recover, but nothing about default operation is "gentle" — treat every run as a live-fire test.


1. Overview

CVE-2026-49975 ("HTTP/2 Bomb") is a remote, unauthenticated Denial-of-Service vulnerability affecting Apache HTTP Server's mod_http2 module. It chains two long-known HTTP/2 weaknesses:

  1. HPACK bookkeeping bomb — a small, HPACK-encoded HTTP/2 request causes multiple Cookie header fragments to be merged without being counted against LimitRequestFields, forcing the server to repeatedly allocate memory for internal header bookkeeping structures.
  2. Flow-control stall (Slowloris-style) — the client advertises a near-zero flow-control window, delaying response transmission and keeping the affected stream(s) open, which prevents the allocated memory from being released.

The result: a single client on a modest connection can force significant, sustained memory allocation on the target for as long as the stream is held open. This implementation supports two payload modes and scales linearly with the concurrency you configure:

  • nginx mode — plants an empty x-bomb header in the HPACK dynamic table and re-references it repeatedly (~70:1 amplification per reference).
  • classic mode — plants an oversized cookie header instead (~4000:1 amplification per reference).

Each connection re-references the planted header thousands of times per stream (--headers, default 5000), across multiple streams per connection (--streams, default 10) and multiple parallel connections (--threads, default 1). If the server closes a connection, the tool reconnects immediately and keeps going until manually stopped — this is a continuous-hold loop, not a single one-shot probe.

Related identifiers for other affected stacks (not implemented or tested by this repo):

  • Envoy → CVE-2026-47774
  • Microsoft IIS, Cloudflare Pingora → tracked separately, no CVE referenced here

Full scope of the underlying weakness class, for completeness — the "HTTP/2 Bomb" technique (HPACK compression bomb + flow-control hold) affects several server implementations beyond Apache. This repo only implements and tests the Apache case; the rest is included so readers understand the broader class, not because this PoC exercises them:

ImplementationStatusImplemented in this PoC?
Apache HTTP Server mod_http2Fixed in httpd 2.4.68 (2026-06-08)Yes — this repo
nginxFixed in 1.29.8No
EnvoyTracked separatelyNo
Microsoft IISTracked separatelyNo
Cloudflare PingoraTracked separatelyNo
CVECVE-2026-49975
CWECWE-789 (Memory Allocation with Excessive Size Value, per NVD/CVE.org); also tracked as CWE-409 (Improper Handling of Highly Compressed Data) by some vendors
CVSS7.5 (High) — CVSS v3.1, availability-only vector (per NVD). Apache's own advisory rates it Moderate.
Affected componentApache HTTP Server mod_http2
Vulnerable versionsApache httpd 2.4.17 ≤ version ≤ 2.4.67 (default HTTP/2 config)
Fixed inApache HTTP Server 2.4.68 (released 2026-06-08). Underlying fix landed upstream in mod_h2 on 2026-05-27, merged into the httpd 2.4.x branch 2026-06-02, shipped in the 2.4.68 release.
Attack typeDenial of Service — memory exhaustion (availability only)
Authentication requiredNo
Data exposure / RCENone — this is availability-impact only
Known exploitedNot currently flagged as known-exploited-in-the-wild by tracked sources.

References (primary sources — verify all claims independently):

  • CVE record: https://www.cve.org/CVERecord?id=CVE-2026-49975
  • NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-49975
  • Apache advisory / vulnerabilities list: https://httpd.apache.org/security/vulnerabilities_24.html
  • Apache 2.4.68 changelog (fix commit reference): https://dlcdn.apache.org/httpd/CHANGES_2.4.68
  • Original discovery writeup: https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb

2. Scope of This Repository

This repository contains:

  • A minimal PoC script that reproduces the hold-only HPACK bomb behavior against a target you are authorized to test.
  • This README, documenting the vulnerability, disclosure timeline, and safe-use conditions.

This repository does not contain:

  • Any automation for scanning the internet for vulnerable hosts.
  • Any flooding/DoS-sustain logic, concurrency ramp-up, or credential/target lists.
  • Any code targeting a specific live system by default. Target must be explicitly supplied by the operator.

3. ⚖️ Legal & Ethical Notice

Read this before doing anything else.

  • This PoC is published strictly for educational and defensive security research purposes — to help operators verify their own exposure and to support the public record of a already-disclosed, already-patched vulnerability.
  • You must have explicit, documented authorization from the system owner before running this against any target that is not your own infrastructure or a system you are contractually/legally authorized to test (e.g., a signed pentest engagement, bug bounty scope, or written permission).
  • Running this PoC against systems you do not own or have authorization to test — including but not limited to government agencies, law enforcement, critical infrastructure, or any third-party production system — without permission is illegal in most jurisdictions (in Indonesia, this falls under UU ITE) and may constitute a criminal offense elsewhere.
  • The author(s) of this repository:
    • Take no responsibility for misuse of this code.
    • Do not condone using this PoC to disrupt, degrade, or deny service to any system without authorization.
    • Provide this code as-is, with no warranty of any kind.
  • If you are a vendor, agency, or system operator who found this repository because your system was tested: see Section 6 — Disclosure Timeline for how this was reported and to whom.

By downloading, cloning, or executing any code in this repository, you agree that you are solely responsible for ensuring you have proper authorization, and that you accept full legal responsibility for your use of it.


4. Recon Method

CVE-2026-49975 only applies to a target that satisfies both criteria in Section 1 — reachable over HTTP/2 and running an in-range, vulnerable mod_http2 version (2.4.17 ≤ version ≤ 2.4.67, default config). A plain curl -vkI against the target's HTTPS port is enough to check both — no scanner or extra flags needed:

curl -vkI https://<target>
Download Tool