CVE-2026-49975: HTTP/2 Denial-of-Service(DoS) Vulnerability in VMware NSX
search cancel

CVE-2026-49975: HTTP/2 Denial-of-Service(DoS) Vulnerability in VMware NSX

book

Article ID: 445782

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

A denial‑of‑service (DoS) vulnerability, registered as CVE‑2026‑49975, has been identified in the HTTP/2 protocol in VMware Cloud Foundation (VCF). 

This security concern can allow an attacker to exploit the HTTP/2 implementation to disrupt services and cause unexpected application downtime.

This article clarifies whether VMware NSX is affected by CVE‑2026‑49975.

Environment

VMware NSX

Resolution

VMware NSX is not affected by CVE-2026-49975.

Broadcom is aware of CVE-2026-49975.
Refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information or support, Contact Broadcom Support