Skip to main content
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-releasedetection-content-update

HTTP/2 Bomb DoS Flaw Crashes Major Web Servers via Memory Exhaustion

Updated 6d agoFirst seen Jun 2, 202614 sources

Researchers publicly disclosed HTTP/2 Bomb, a remote denial-of-service technique that abuses standard HTTP/2 behavior to rapidly exhaust memory on major web servers and proxies, including nginx, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora. The attack combines HPACK header-compression amplification with a Slowloris-style flow-control stall, letting a low-bandwidth client trigger disproportionate server-side allocations and keep that memory pinned by advertising a zero-byte window. Reports said a single machine on a 100 Mbps connection could make vulnerable services inaccessible within seconds, with testing showing Apache httpd and Envoy consuming roughly 32 GB of RAM in about 10 to 20 seconds under default HTTP/2 configurations.

Public disclosures and proof-of-concept code indicated the amplification largely comes from per-header bookkeeping rather than oversized decoded header values, allowing common decoded-size limits to be bypassed. Apache tracked its exposure as CVE-2026-49975 and released a fix in mod_http2 2.0.41, while nginx addressed the issue in 1.29.8; advisories initially said IIS, Envoy, and Pingora lacked patches, though later disclosures showed Envoy assigned CVE-2026-47774 and published an advisory. Researchers estimated more than 880,000 internet-exposed HTTP/2 systems could be affected and recommended upgrading where fixes exist, or otherwise disabling HTTP/2, enforcing strict header-count limits, and monitoring for abnormal memory growth.

Share:
HTTP/2 Bomb DoS Flaw Crashes Major Web Servers via Memory Exhaustion
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jun 5, 202610d ago

Further reporting highlighted HTTP/2 Bomb as a standards-level issue

Subsequent coverage emphasized that HTTP/2 Bomb stems from standard HTTP/2 and HPACK behavior rather than a single implementation flaw, and reiterated that nginx and Apache had fixes while patches for IIS, Envoy, and Pingora were still unavailable. The reporting also highlighted the role of AI-assisted analysis in combining previously known techniques.

DoS-атака HTTP/2 Bomb за считаные секунды выводит из строя веб-серверы - Хакер
Jun 4, 202611d ago

Cloudflare disputed Pingora needed a patch; Microsoft said it was investigating

Reporting on the disclosure said Cloudflare disputed that Pingora required a patch, arguing its architecture and DDoS protections already mitigated the attack. The same report said Microsoft was investigating mitigations for IIS.

OpenAI's Codex chains decade-old DoS techniques into HTTP/2 Bomb
Jun 3, 202612d ago

nginx was notified and fixed HTTP/2 Bomb in version 1.29.8

One source states nginx was notified in April about the HTTP/2 Bomb issue and added a fix in nginx version 1.29.8. Multiple references identify 1.29.8 as the patched version for nginx.

HTTP/2 Bomb Exploit Details and PoC Publicly Disclosed

Public reporting detailed HTTP/2 Bomb exploit and exposure scope

News and security outlets reported technical details of HTTP/2 Bomb, including that a single client could pin roughly 32 GB of memory on Apache httpd and Envoy in about 20 seconds and that more than 880,000 internet-exposed systems might be vulnerable. These reports also noted that IIS, Envoy, and Pingora lacked patches at that time.

HTTP/2 Bomb Exploit Details and PoC Publicly Disclosed

Envoy published advisory for related memory exhaustion flaw

Envoy published a security advisory describing an HTTP/2 downstream request processing vulnerability that can cause excessive memory consumption and OOM termination. The advisory said the attack could be further amplified by HTTP/2 flow-control stalling, linking it to the broader HTTP/2 Bomb technique.

HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification · Advisory · envoyproxy/envoy · GitHub
Jun 2, 202613d ago

Calif published companion GitHub repository with verified PoCs

A companion GitHub repository for the HTTP/2 Bomb research was published with self-contained proof-of-concept directories for Envoy, Apache httpd, nginx, Microsoft IIS, and Cloudflare Pingora. The repository said the exploits were verified and functional and documented amplification ratios across targets.

publications/MADBugs/http2-bomb at main · califio/publications · GitHub

Calif publicly disclosed the HTTP/2 Bomb technique

Researchers publicly disclosed HTTP/2 Bomb, a denial-of-service technique that combines HPACK compression abuse with HTTP/2 flow-control stalling to exhaust memory on major web servers under default configurations. The disclosure named nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora as affected implementations.

oss-sec: HTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora
May 27, 202619d ago

Apache was notified and released same-day fix for CVE-2026-49975

A source says Apache was notified on May 27 and released a fix the same day for the HTTP/2 Bomb issue, tracked as CVE-2026-49975 in mod_http2 v2.0.41. Other references corroborate that Apache assigned the CVE and made the fix available.

HTTP/2 Bomb Exploit Details and PoC Publicly Disclosed
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Affected products
9 linked
Apache Http ServerPingoraInternet Information ServicesNginxWindows ServerNginxIisCodexH2o
Organizations
14 linked
CloudflareMicrosoft CorporationOpenaiCalifApache Software FoundationOracleCodexNginxBleepingComputerSecurityWeekEnvoy AirCrowdStrikeF5Google
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.