<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mod_http2 — PoC Archive</title><link>https://poc.intelseclab.com/tags/mod_http2/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/mod_http2/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</guid><description>High severity — network · CVE-2026-49975. Status: PoC. Affects: Apache HTTP Server (mod_http2). Tags: apache, httpd, http2, hpack, mod_http2, cookie-header, memory-exhaustion, denial-of-service, flow-control.</description><category>network</category><category>High</category><category>apache</category><category>httpd</category><category>http2</category><category>hpack</category><category>mod_http2</category><category>cookie-header</category><category>memory-exhaustion</category><category>denial-of-service</category><category>flow-control</category></item><item><title>Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</guid><description>Critical severity — web · CVE-2026-23918. Status: Weaponized. Affects: Apache HTTP Server (httpd) with mod_http2. Tags: RCE, pre-auth, unauthenticated, double-free, heap-corruption, Apache, httpd, mod_http2, HTTP/2, TLS.</description><category>web</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>double-free</category><category>heap-corruption</category><category>Apache</category><category>httpd</category><category>mod_http2</category><category>HTTP/2</category><category>TLS</category></item></channel></rss>