#1138794 nginx: HTTP/2 Bomb: Remote DoS against nginx

Package:
nginx
Source:
nginx
Description:
small, powerful, scalable web/proxy server
Submitter:
Benjamin Sonntag
Date:
2026-07-07 19:05:01 UTC
Severity:
normal
Tags:
#1138794#5
Date:
2026-06-03 20:58:26 UTC
From:
To:
Dear Maintainer,

I just found about this CVE here:
https://discourse.ifin.network/t/cve-2026-49975-http-2-bomb-remote-dos-against-most-major-web-servers/536

which applies to nginx as packaged by Debian Trixie and before (as soon as HTTP/2 is supported on Nginx)

Nginx added a max_headers directive to prevent the exploitation of this security issue here:
https://github.com/nginx/nginx/commit/365694160a85229a7cb006738de9260d49ff5fa2

I tested the POC (./hpack_bomb.py --host 127.0.0.1 --port 443 --connections 15) on a stock trixie nginx and it used 3.2G of memory immediately

I guess adding max_headers + changing the nginx default conf to put a sensible value there would be a good idea.

Thanks for your attention,

Benjamin

#1138794#10
Date:
2026-06-03 21:08:54 UTC
From:
To:
Hi,

The CVE is for apache httpd specific, so I'm removing this from the
subject. The CNA responsible for nginx has been asked about a nginx
specific assignment.

Regards,
Salvatore

#1138794#31
Date:
2026-06-04 00:39:15 UTC
From:
To:
Hello,
should be the default value. Source: https://github.com/nginx/nginx/pull/1116/changes

#1138794#32
Date:
2026-07-07 18:19:37 UTC
From:
To:
Hello,

Bug #1138794 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/37297a5094f0d6c560fb5a259f4d7bda543518dd
------------------------------------------------------------------------ Import Debian changes 1.18.0-6.1+deb11u8 nginx (1.18.0-6.1+deb11u8) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bullseye. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream; (Closes: #1140361) - FIX-HTTP2bomb.patch: backport from upstream. (Closes: #1138794) . nginx (1.18.0-6.1+deb11u7) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/patches/CVE-2026-9256.patch: cherry-pick from upstream. (Closes: #1137339) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1138794
#1138794#33
Date:
2026-07-07 19:02:35 UTC
From:
To:
Hello,

Bug #1138794 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/37297a5094f0d6c560fb5a259f4d7bda543518dd
------------------------------------------------------------------------ Import Debian changes 1.18.0-6.1+deb11u8 nginx (1.18.0-6.1+deb11u8) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bullseye. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream; (Closes: #1140361) - FIX-HTTP2bomb.patch: backport from upstream. (Closes: #1138794) . nginx (1.18.0-6.1+deb11u7) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/patches/CVE-2026-9256.patch: cherry-pick from upstream. (Closes: #1137339) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1138794