CyCognito Highlights Apache HTTP/2 Bomb Risk as CVE-2026-49975 Targets Server Availability
CyCognito has published an emerging threat analysis on CVE-2026-49975, an Apache HTTP Server vulnerability that can allow denial of service through memory exhaustion in HTTP/2 handling. The vulnerability affects the mod_http2 module and is associated with a technique CyCognito identified as the “HTTP/2 Bomb.” In CyCognito’s...
Read more



















