CVE-2026-49975 | Apache HTTP Server mod_http2 modules/http2/h2_util.c req_add_header HTTP/2 Bomb denial of service (EUVD-2026-35105 / Nessus ID 319609)
A vulnerability categorized as critical has been discovered in Apache HTTP Server. This impacts the function req_add_header of the file modules/http2/h2_util.c of the component mod_http2. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2026-49975. The attack may be performed from remote. In addition, an exploit is available.
It is best practice to apply a patch to resolve this issue.