VMware Identity Manager Impact Analysis for CVE-2026-49975 ((HTTP/2 Bomb) and CVE-2026-9256 (Nginx-Poolslip)
search cancel

VMware Identity Manager Impact Analysis for CVE-2026-49975 ((HTTP/2 Bomb) and CVE-2026-9256 (Nginx-Poolslip)

book

Article ID: 444601

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

This article provides an assessment of VMware Identity Manager regarding two recently announced security vulnerabilities.

Concerns regarding susceptibility to Denial of Service (DoS) via HTTP/2 frame exploitation or directory traversal/vulnerabilities within Nginx modules.

CVE-2026-49975 (HTTP/2 Bomb): A denial-of-service vulnerability in Envoy's HTTP/2 request-processing code where crafted sequences of frames drive abnormal memory growth or CPU consumption.

CVE-2026-9256 (Nginx-Poolslip): A vulnerability involving the `ngx_http_rewrite_module` in specific Nginx configurations.

Environment

VMware Identity Manager 3.3.7 (21173100)

Resolution

Broadcom is aware of CVE-2026-49975 ((HTTP/2 Bomb) and CVE-2026-9256 (Nginx-Poolslip).

Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.

Should you require further information please contact Broadcom Support.

Additional Information

https://nvd.nist.gov/vuln/detail/CVE-2026-9256

https://nvd.nist.gov/vuln/detail/CVE-2026-49975