Inquiry Regarding Mitigation for CVE-2026-49975 (HTTP/2 Bomb) on Azure Application Gateway WAF

Katsutoshi Yotsuyanagi 0 評価のポイント
2026-06-17T05:59:22.8966667+00:00

We are currently assessing the impact of CVE-2026-49975 ("HTTP/2 Bomb") on our customers' environments and would appreciate your guidance regarding Azure Application Gateway WAF.

We would like to confirm the following:

Is Azure Application Gateway WAF affected by CVE-2026-49975 (HTTP/2 Bomb)?

Has Microsoft implemented any mitigations or protections against this attack within Azure Application Gateway WAF?

Are there any recommended configurations, WAF policies, rate-limiting rules, or best practices to mitigate this threat?

Are there any plans to add specific detection or mitigation capabilities for CVE-2026-49975?

Will information related to CVE-2026-49975 be included in the MS-ThreatIntel-CVEs feed?

Our current understanding is that Azure Application Gateway WAF does not provide explicit controls for HTTP/2 header expansion limits, HPACK table limits, or total header size restrictions. We would appreciate clarification on whether any platform-level protections are already in place.

Thank you for your assistance. We look forward to your response.

Azure Web Application Firewall

お客様の回答

質問作成者は回答に "承認済み"、モデレーターは "推奨" とマークできます。これにより、ユーザーは作成者の問題が回答によって解決したことを把握できます。