Description
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Windows HTTP.sys permits an attacker to create an unbounded allocation of system resources without any imposed limits or throttling. This allows the host to exhaust critical resources, leading to a denial of service condition where legitimate network requests cannot be served. The weakness is classified as CWE-770, which describes an unbounded resource allocation flaw.

Affected Systems

The vulnerability impacts Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025—including Server Core installations. Any machine running HTTP.sys from these operating systems on any architecture (x86, x64, arm64) is susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates a medium‑high severity. less than 1% suggests that, at present, exploitation is not listed in CISA’s KEV catalog. The likely attack vector is remote, over a network: an adversary can craft specific HTTP requests to a vulnerable host, causing resource exhaustion. While the flaw does not grant code execution or privilege escalation, it can make the target unresponsive, impacting availability for critical services.

Generated by OpenCVE AI on July 31, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch for CVE-2026-49787 to all affected Windows and Windows Server installations.
  • If patching cannot be performed immediately, restrict the exposed HTTP traffic to trusted networks or use firewall rules to limit request rates, thereby mitigating the potential for resource exhaustion.
  • Enable monitoring of HTTP.sys resource usage and set alerts for abnormal consumption patterns so that administrators can detect and respond to denial-of-service attempts early.

Generated by OpenCVE AI on July 31, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
Title HTTP.sys Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-770
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:14.791Z

Reserved: 2026-06-01T17:02:37.207Z

Link: CVE-2026-49787

cve-icon Vulnrichment

Updated: 2026-07-14T19:18:17.354Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:00:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling