Researchers publicly disclosed HTTP/2 Bomb, a remote denial-of-service technique that abuses standard HTTP/2 behavior to rapidly exhaust memory on major web servers and proxies, including nginx, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora. The attack combines HPACK header-compression amplification with a Slowloris-style flow-control stall, letting a low-bandwidth client trigger disproportionate server-side allocations and keep that memory pinned by advertising a zero-byte window. Reports said a single machine on a 100 Mbps connection could make vulnerable services inaccessible within seconds, with testing showing Apache httpd and Envoy consuming roughly 32 GB of RAM in about 10 to 20 seconds under default HTTP/2 configurations.
Public disclosures and proof-of-concept code indicated the amplification largely comes from per-header bookkeeping rather than oversized decoded header values, allowing common decoded-size limits to be bypassed. Apache tracked its exposure as CVE-2026-49975 and released a fix in mod_http2 2.0.41, while nginx addressed the issue in 1.29.8; advisories initially said IIS, Envoy, and Pingora lacked patches, though later disclosures showed Envoy assigned CVE-2026-47774 and published an advisory. Researchers estimated more than 880,000 internet-exposed HTTP/2 systems could be affected and recommended upgrading where fixes exist, or otherwise disabling HTTP/2, enforcing strict header-count limits, and monitoring for abnormal memory growth.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage emphasized that HTTP/2 Bomb stems from standard HTTP/2 and HPACK behavior rather than a single implementation flaw, and reiterated that nginx and Apache had fixes while patches for IIS, Envoy, and Pingora were still unavailable. The reporting also highlighted the role of AI-assisted analysis in combining previously known techniques.
Reporting on the disclosure said Cloudflare disputed that Pingora required a patch, arguing its architecture and DDoS protections already mitigated the attack. The same report said Microsoft was investigating mitigations for IIS.
One source states nginx was notified in April about the HTTP/2 Bomb issue and added a fix in nginx version 1.29.8. Multiple references identify 1.29.8 as the patched version for nginx.
News and security outlets reported technical details of HTTP/2 Bomb, including that a single client could pin roughly 32 GB of memory on Apache httpd and Envoy in about 20 seconds and that more than 880,000 internet-exposed systems might be vulnerable. These reports also noted that IIS, Envoy, and Pingora lacked patches at that time.
Envoy published a security advisory describing an HTTP/2 downstream request processing vulnerability that can cause excessive memory consumption and OOM termination. The advisory said the attack could be further amplified by HTTP/2 flow-control stalling, linking it to the broader HTTP/2 Bomb technique.
A companion GitHub repository for the HTTP/2 Bomb research was published with self-contained proof-of-concept directories for Envoy, Apache httpd, nginx, Microsoft IIS, and Cloudflare Pingora. The repository said the exploits were verified and functional and documented amplification ratios across targets.
Researchers publicly disclosed HTTP/2 Bomb, a denial-of-service technique that combines HPACK compression abuse with HTTP/2 flow-control stalling to exhaust memory on major web servers under default configurations. The disclosure named nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora as affected implementations.
A source says Apache was notified on May 27 and released a fix the same day for the HTTP/2 Bomb issue, tracked as CVE-2026-49975 in mod_http2 v2.0.41. Other references corroborate that Apache assigned the CVE and made the fix available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
bugflation.com
Open sourcemy.f5.com
Open sourcesocprime.com
Open sourcexakep.ru
Open sourceseclists.org
Open sourceblog.calif.io
Open sourcegithub.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.