"We’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers" "We disclosed to Apache on May 27, and Stefan Eissing fixed it on the same day by making cookie headers count against LimitRequestFields. The issue was assigned CVE-2026-49975."