CVE-2026-49975: HTTP/2 Denial-of-Service(DoS) Vulnerability in VCF Components
search cancel

CVE-2026-49975: HTTP/2 Denial-of-Service(DoS) Vulnerability in VCF Components

book

Article ID: 445446

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • A denial-of-service (DoS) vulnerability, registered as CVE-2026-49975, has been identified in the HTTP/2 protocol in VCF Operations, VCF Automation and VCF Operations for Logs.
  • This security concern can allow an attacker to exploit the HTTP/2 implementation to disrupt services and cause unexpected application downtime.

Environment

VCF Operations 9.0.1

VCF Operations for Logs 9.0.1

VCF Automation 9.0.1

Resolution

VMware By Broadcom is aware of CVE-2026-49975.
Refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information or support, Contact Broadcom Support