This article provides an assessment of VMware Identity Manager regarding two recently announced security vulnerabilities.
Concerns regarding susceptibility to Denial of Service (DoS) via HTTP/2 frame exploitation or directory traversal/vulnerabilities within Nginx modules.
CVE-2026-49975 (HTTP/2 Bomb): A denial-of-service vulnerability in Envoy's HTTP/2 request-processing code where crafted sequences of frames drive abnormal memory growth or CPU consumption.
CVE-2026-9256 (Nginx-Poolslip): A vulnerability involving the `ngx_http_rewrite_module` in specific Nginx configurations.
VMware Identity Manager 3.3.7 (21173100)
Broadcom is aware of CVE-2026-49975 ((HTTP/2 Bomb) and CVE-2026-9256 (Nginx-Poolslip).
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information please contact Broadcom Support.