CVE-2026-49975: exploitation status and patch state
CVE-2026-49975 · CVSS 7.5 HIGH · EPSS 28% · patch available
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Is CVE-2026-49975 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 28%.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
CBL-Mariner Releases
What PlainSec published about CVE-2026-49975
PlainSec has not published a story about this CVE.