Web アプリの保護を提供する Azure サービス。
Inquiry Regarding Mitigation for CVE-2026-49975 (HTTP/2 Bomb) on Azure Application Gateway WAF
We are currently assessing the impact of CVE-2026-49975 ("HTTP/2 Bomb") on our customers' environments and would appreciate your guidance regarding Azure Application Gateway WAF.
We would like to confirm the following:
Is Azure Application Gateway WAF affected by CVE-2026-49975 (HTTP/2 Bomb)?
Has Microsoft implemented any mitigations or protections against this attack within Azure Application Gateway WAF?
Are there any recommended configurations, WAF policies, rate-limiting rules, or best practices to mitigate this threat?
Are there any plans to add specific detection or mitigation capabilities for CVE-2026-49975?
Will information related to CVE-2026-49975 be included in the MS-ThreatIntel-CVEs feed?
Our current understanding is that Azure Application Gateway WAF does not provide explicit controls for HTTP/2 header expansion limits, HPACK table limits, or total header size restrictions. We would appreciate clarification on whether any platform-level protections are already in place.
Thank you for your assistance. We look forward to your response.