
Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2
Security Research PoC by naheeju
⚠️ This is a working, memory-exhaustion DoS tool — not a toy. It opens streams that force the target to allocate memory and holds them open via HTTP/2 flow-control tricks. As long as the process is running, it keeps holding and automatically reconnects if the server drops the connection — it does not stop on its own. Impact scales directly with
--threads,--streams, and--headers. Stopping the process (Ctrl+C) releases the held streams and lets the server recover, but nothing about default operation is "gentle" — treat every run as a live-fire test.
CVE-2026-49975 ("HTTP/2 Bomb") is a remote, unauthenticated Denial-of-Service vulnerability affecting Apache HTTP Server's mod_http2 module. It chains two long-known HTTP/2 weaknesses:
Cookie header fragments to be merged without being counted against LimitRequestFields, forcing the server to repeatedly allocate memory for internal header bookkeeping structures.The result: a single client on a modest connection can force significant, sustained memory allocation on the target for as long as the stream is held open. This implementation supports two payload modes and scales linearly with the concurrency you configure:
nginx mode — plants an empty x-bomb header in the HPACK dynamic table and re-references it repeatedly (~70:1 amplification per reference).classic mode — plants an oversized cookie header instead (~4000:1 amplification per reference).Each connection re-references the planted header thousands of times per stream (--headers, default 5000), across multiple streams per connection (--streams, default 10) and multiple parallel connections (--threads, default 1). If the server closes a connection, the tool reconnects immediately and keeps going until manually stopped — this is a continuous-hold loop, not a single one-shot probe.
Related identifiers for other affected stacks (not implemented or tested by this repo):
CVE-2026-47774Full scope of the underlying weakness class, for completeness — the "HTTP/2 Bomb" technique (HPACK compression bomb + flow-control hold) affects several server implementations beyond Apache. This repo only implements and tests the Apache case; the rest is included so readers understand the broader class, not because this PoC exercises them:
| Implementation | Status | Implemented in this PoC? |
|---|---|---|
Apache HTTP Server mod_http2 | Fixed in httpd 2.4.68 (2026-06-08) | Yes — this repo |
| nginx | Fixed in 1.29.8 | No |
| Envoy | Tracked separately | No |
| Microsoft IIS | Tracked separately | No |
| Cloudflare Pingora | Tracked separately | No |
| CVE | CVE-2026-49975 |
| CWE | CWE-789 (Memory Allocation with Excessive Size Value, per NVD/CVE.org); also tracked as CWE-409 (Improper Handling of Highly Compressed Data) by some vendors |
| CVSS | 7.5 (High) — CVSS v3.1, availability-only vector (per NVD). Apache's own advisory rates it Moderate. |
| Affected component | Apache HTTP Server mod_http2 |
| Vulnerable versions | Apache httpd 2.4.17 ≤ version ≤ 2.4.67 (default HTTP/2 config) |
| Fixed in | Apache HTTP Server 2.4.68 (released 2026-06-08). Underlying fix landed upstream in mod_h2 on 2026-05-27, merged into the httpd 2.4.x branch 2026-06-02, shipped in the 2.4.68 release. |
| Attack type | Denial of Service — memory exhaustion (availability only) |
| Authentication required | No |
| Data exposure / RCE | None — this is availability-impact only |
| Known exploited | Not currently flagged as known-exploited-in-the-wild by tracked sources. |
References (primary sources — verify all claims independently):
This repository contains:
This repository does not contain:
Read this before doing anything else.
By downloading, cloning, or executing any code in this repository, you agree that you are solely responsible for ensuring you have proper authorization, and that you accept full legal responsibility for your use of it.
CVE-2026-49975 only applies to a target that satisfies both criteria in Section 1 — reachable over HTTP/2 and running an in-range, vulnerable mod_http2 version (2.4.17 ≤ version ≤ 2.4.67, default config). A plain curl -vkI against the target's HTTPS port is enough to check both — no scanner or extra flags needed:
curl -vkI https://<target>