Skip to content
Oracle Linux 10 mod_http2 DoS Vulnerabilities Disclosed

Oracle Linux 10 mod_http2 DoS Vulnerabilities Disclosed

First seen 20 Jul 2026, 23:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 21, 2026 at 22:53 UTC
  • Oracle Linux 10 mod_http2 has multiple DoS vulnerabilities disclosed.
  • CVE-2026-49975 allows remote DoS via compression bomb and Slowloris-style attacks.
  • Users are urged to apply patches immediately to prevent service disruptions.

Oracle has released advisories for multiple denial-of-service (DoS) vulnerabilities affecting mod_http2 in Oracle Linux 10. The vulnerabilities include CVE-2026-43951, CVE-2026-48913, and CVE-2026-49975, all published on 2026-06-08. CVE-2026-49975 specifically allows for remote DoS attacks via compression bomb and Slowloris-style techniques. The vulnerabilities impact Apache HTTP Server's mod_http2 module, which is crucial for handling HTTP/2 requests. Users are advised to update to the patched versions to mitigate these risks. The vulnerabilities could lead to significant service disruptions if exploited. The advisory emphasizes the importance of applying the updates promptly to safeguard systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 52d ago How this analysis works

Timeline

2025-07-10
CVE-2025-53020 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
First public PoC for CVE-2026-49975
A proof of concept for exploiting CVE-2026-49975 was made public, increasing the urgency for patching.
Linuxsecurity
2026-06-08
CVE-2026-43951, CVE-2026-48913, CVE-2026-49975 published
Oracle disclosed multiple DoS vulnerabilities in mod_http2 affecting Oracle Linux 10.
Linuxsecurity
2026-07-20
Oracle releases advisory for mod_http2 vulnerabilities
Oracle advises users to update to patched versions of mod_http2 to mitigate the disclosed vulnerabilities.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2025-53020 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed