<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Http2 — PoC Archive</title><link>https://poc.intelseclab.com/tags/http2/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/http2/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</guid><description>High severity — binary · CVE-2026-49160. Status: PoC. Affects: Windows HTTP.sys kernel-mode driver (Windows 10 build 26100 confirmed in crash logs). Tags: windows, http.sys, kernel, http2, dos, bsod, memory-corruption, integer-overflow.</description><category>binary</category><category>High</category><category>windows</category><category>http.sys</category><category>kernel</category><category>http2</category><category>dos</category><category>bsod</category><category>memory-corruption</category><category>integer-overflow</category></item><item><title>NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42926-nginx-http2-frame-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42926-nginx-http2-frame-injection/</guid><description>High severity — web · CVE-2026-42926. Status: PoC. Affects: NGINX (HTTP/2 upstream proxying). Tags: nginx, http2, frame-injection, reverse-proxy, request-smuggling, docker-lab.</description><category>web</category><category>High</category><category>nginx</category><category>http2</category><category>frame-injection</category><category>reverse-proxy</category><category>request-smuggling</category><category>docker-lab</category></item><item><title>gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33186-grpc-go-rbac-authz-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33186-grpc-go-rbac-authz-bypass/</guid><description>High severity — network · CVE-2026-33186 (GHSA-p77j-4mvh-x3m3). Status: PoC. Affects: google.golang.org/grpc (grpc-go) authz package (SDK-level RBAC). Tags: grpc, grpc-go, rbac, authorization-bypass, http2, path-normalization, golang, access-control.</description><category>network</category><category>High</category><category>grpc</category><category>grpc-go</category><category>rbac</category><category>authorization-bypass</category><category>http2</category><category>path-normalization</category><category>golang</category><category>access-control</category></item><item><title>Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</guid><description>High severity — network · CVE-2026-49975. Status: PoC. Affects: Apache HTTP Server (mod_http2). Tags: apache, httpd, http2, hpack, mod_http2, cookie-header, memory-exhaustion, denial-of-service, flow-control.</description><category>network</category><category>High</category><category>apache</category><category>httpd</category><category>http2</category><category>hpack</category><category>mod_http2</category><category>cookie-header</category><category>memory-exhaustion</category><category>denial-of-service</category><category>flow-control</category></item></channel></rss>