Back Linuxsecurity Oracle Linux 9 mod_http2 Important Remote DoS Advisory ELSA-2026
[2.0.26-6.1] - Resolves: RHEL-182417 - mod_http2: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) [2.0.26-6] - Resolves: RHEL-166293 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)
[2.0.26-6.1] - Resolves: RHEL-182417 - mod_http2: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) [2.0.26-6] - Resolves: RHEL-166293 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)
mod_http2-2.0.26-6.el9_8.1.x86_64.rpm
mod_http2-2.0.26-6.el9_8.1.x86_64.rpm
mod_http2-2.0.26-6.el9_8.1.aarch64.rpm
mod_http2-2.0.26-6.el9_8.1.aarch64.rpm
Related CVEs: CVE-2026-49975
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
