CVE-2026-49975, also known as HTTP/2 Bomb, is a remote denial-of-service exploit against most major web servers, including: nginx, Apache httpd, Microsoft IIS, Envoy, Cloudflare Pingor. The vulnerable behavior exists in each server's default HTTP/2 configuration
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb