CVE-2026-49160
HIGHMicrosoft Windows HTTP.sys HTTP/2 - Denial of Service
Title source: manualExploitation Summary
EIP tracks 3 public exploits for CVE-2026-49160. PoCs published by HORKimhab, dhmosfunk.
AI-analyzed exploit summary The repository contains no actual exploit code or technical details about CVE-2026-49160, instead linking to external GitHub repositories and an encrypted archive hosted on a third-party storage service. This is a hallmark of social engineering lures.
Description
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
Exploits (3)
The repository contains no actual exploit code or technical details about CVE-2026-49160, instead linking to external GitHub repositories and an encrypted archive hosted on a third-party storage service. This is a hallmark of social engineering lures.
This repository contains a functional Python-based PoC for CVE-2026-49160 and CVE-2026-47291, targeting HTTP.sys vulnerabilities. The exploit leverages HTTP/2 header manipulation to trigger a denial-of-service (DoS) condition, with detailed technical analysis provided in the README.
This repository contains a functional Python script that exploits CVE-2026-49160, a denial-of-service vulnerability in HTTP.sys. The exploit sends a crafted HTTP/2 request with an excessive number of headers to trigger the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H