elsa-2026-25057
oracle_linux
Description
[2.0.26-6.1] - Resolves: RHEL-182417 - mod_http2: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) [2.0.26-6] - Resolves: RHEL-166293 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-49975"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[2.0.26-6.1]\n- Resolves: RHEL-182417 - mod_http2: HTTP/2: Remote Denial of Service via\n compression bomb and Slowloris-style attack (CVE-2026-49975)\n\n[2.0.26-6]\n- Resolves: RHEL-166293 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory\n Increase (CVE-2025-53020)",
"id": "ELSA-2026-25057",
"ovalId": "oval:com.oracle.elsa:def:202625057",
"source": "oracle_linux",
"title": "ELSA-2026-25057: mod_http2 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-25057.html"
}