CVE-2026-49975
Apache Software Foundation Apache HTTP Server, JBoss Core Services for RHEL 8, JBoss Core Services on RHEL 7
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
- CVSS
- 7.5
- EPSS
- 28.0% 97.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.09