|
Jun 3 |
Posted by Lee Blakely on 03 June 2026 11:06 AM
|
|
Posted: June 3, 2026 Reliable Penguin is aware of public reports regarding CVE-2026-49975, also referred to as the HTTP/2 Bomb vulnerability. This issue may allow a remote attacker to exhaust server memory on affected HTTP/2-enabled web servers, potentially causing service disruption or denial of service. Public reporting indicates that the issue relates to HTTP/2 header compression behavior and may affect multiple web server and proxy implementations, including NGINX, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora. Current statusReliable Penguin is reviewing managed server environments and applying appropriate mitigations. At this point, no customer action is necessary. We will provide updates as they become available. What customers should doNo action is required from Reliable Penguin managed hosting customers at this time. Customers with questions may open a support request through the Reliable Penguin help desk. References
| |