CVEFinder.io

CVE-2026-49975

âš ī¸ high
🔍 Scan for this CVE
Summary

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

CVSS Score
7.5
High
EPSS Score
31.0
Exploit Probability
Published Date
2026-06-08
First Seen: 2026-06-09
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.0% of all 349,016 vulnerabilities in our database.

#111,749
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Jun 18, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Partial
Limited system impact
🏆 Discovered By
Quang Luong of Calif.IO in collaboration with OpenAI Codex
SSVC data provided by CISA
Last Modified 2026-08-19
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 3

🔗 References 22

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-12996 âš ī¸ high 8.1 0.5 A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten... 2026-07-30
CVE-2026-14355 đŸ”ļ medium 5.6 0.3 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo... 2026-07-03
CVE-2026-56968 â„šī¸ low 3.7 0.3 GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could... 2026-06-23
CVE-2026-29167 ⛔ critical 9.8 0.7 Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apac... 2026-06-08
CVE-2026-29170 đŸ”ļ medium 6.1 0.5 A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.... 2026-06-08
CVE-2026-34355 âš ī¸ high 7.5 1.1 A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. U... 2026-06-08
These CVEs affect the same products