Impact of HTTP/2 Bomb and mod_http2 vulnerabilities on VMware ESXi
search cancel

Impact of HTTP/2 Bomb and mod_http2 vulnerabilities on VMware ESXi

book

Article ID: 444484

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Security scanners may report that your VMware ESXi 8.x or 7.x hosts are vulnerable to the following CVEs:

  • CVE-2016-1546
  • CVE-2016-6581
  • CVE-2016-8740
  • CVE-2025-53020
  • CVE-2026-49975

Environment

VMware vSphere ESXi

Resolution

Broadcom is aware of the above listed CVEs. Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE. Should you require further information please contact  Broadcom Support.