Security Update: HTTP/2 BOMB Vulnerability Mitigation

Status
Not open for further replies.

Pierre_3CX

Staff member
3CX Support
Joined
Aug 1, 2013
Messages
781
Reaction score
401

HTTP/2 Bomb — CVE-2026-49975 · Full Disclosure · June 8, 2026​

A recently disclosed denial-of-service vulnerability, known as HTTP/2 Bomb (CVE-2026-49975), affects multiple web server implementations. CVE-2026-49975, also known as HTTP/2 Bomb, is a remote denial-of-service exploit against most major web servers, including ng...
Continue reading the Original Blog Post.
 
Last edited by a moderator:
Thanks for being on top of these and acting fast! Installed. No issues.
 
We really appreciate the quick hotfix and detailed follow-up with after action analysis. Much appreciated!
 
Thank you for the heads-up! We expect to see a lot more security issues in open source software components and even components that can be easily de-compiled because they are being scanned for vulnerabilities with AI by hackers. As well as software authors of course but it takes time to fix everything that is being found. At a rate impossible until now.

So system admins should be a lot more vigilant in the coming year - after which of course the positive effects of more secure software should start to pay off. However be prepared for 2026 to be a big year for vulnerabilities and fixes - keep monitoring those blogs and emails with extra vigilance. (Debian, 3CX etc etc)

We are working on some security update improvements for update 10.

Also ...1 . Update, 2. Update, 3. Update
 
Thank you for the heads-up! We expect to see a lot more security issues in open source software components and even components that can be easily de-compiled because they are being scanned for vulnerabilities with AI by hackers. As well as software authors of course but it takes time to fix everything that is being found. At a rate impossible until now.

So system admins should be a lot more vigilant in the coming year - after which of course the positive effects of more secure software should start to pay off. However be prepared for 2026 to be a big year for vulnerabilities and fixes - keep monitoring those blogs and emails with extra vigilance. (Debian, 3CX etc etc)

We are working on some security update improvements for update 10.

Also ...1 . Update, 2. Update, 3. Update
The speed and transparency with which 3CX responds to these matters is something many other companies could learn from. This, combined with the fact that you can rely on auto updates not breaking things, is GOLD!
 

Attachments

  • 1781012316076.png
    1781012316076.png
    332.2 KB · Views: 4
all our systems updated this weekend on normal rotation, thanks a bunch for the super fast fix on this!
 
The speed and transparency with which 3CX responds to these matters is something many other companies could learn from. This, combined with the fact that you can rely on auto updates not breaking things, is GOLD!
I agree. It is nice that 3cx QA's the patches before being released and approves them. Rather than you finding out a patch breaks the system.
 
Update breaks installations, which use a reverse proxy in front of the Nginx and therefore use the "ngx_http_realip_module" module to let the 3CX see the correct client ip addresses. This module seems to have been striped from the now "slimmed down" version of Nginx.
I would highly appreciate, if this module would be reintegrated into the slimmed down version of Nginx.
 
  • Like
Reactions: eBizz
Can I check if this update was pushed to install on self hosted systems? we have some self hosted systems which seem to have updated to the 1131 release but auto updates were not enabled?
 
Can I check if this update was pushed to install on self hosted systems? we have some self hosted systems which seem to have updated to the 1131 release but auto updates were not enabled?
Hi @TerryKC please check your audit log --- type of change Updates
 
Hi @TerryKC please check your audit log --- type of change Updates
I've checked the audit log for updates and there's nothing in any of the 3CX instances mentioning an update to 1131 (only updates for previous versions like update 8). I've checked all the logs and the only entries I can see across all instances with auto update disabled is that the SIP server restarted just before midnight BST on 5 June. All these are self hosted with auto update disabled, or update set to a different day of the week.

It's not caused an issue, I just wanted to see if the update was pushed to self hosted, and wondered why services across different 3CX's restarted at similar times on Friday 5 June.
 
3CX does not push any updates unless you are 3CX hosted. We don't have any access. Unless you have auto updates on, nothing gets pushed automatically.
 
Last edited:
3CX does not push any updates unless you are 3CX hosted. We don't have any access. Unless you have auto updates on, nothing gets pushed automatically.
Thanks for clarifying, I will check with our partners to see if they did the updates.
 
Thank you for the heads-up! We expect to see a lot more security issues in open source software components and even components that can be easily de-compiled because they are being scanned for vulnerabilities with AI by hackers. As well as software authors of course but it takes time to fix everything that is being found. At a rate impossible until now.

So system admins should be a lot more vigilant in the coming year - after which of course the positive effects of more secure software should start to pay off. However be prepared for 2026 to be a big year for vulnerabilities and fixes - keep monitoring those blogs and emails with extra vigilance. (Debian, 3CX etc etc)

We are working on some security update improvements for update 10.

Also ...1 . Update, 2. Update, 3. Update
Perhaps worthwhile looking at an option to have daily update as a schedule for high severity updates to ensure these CVE's are looked at more regularly than a weekly schedule? (ie different schedule for 3CX updates to critical CVE updates).
 
Last edited:
  • Like
Reactions: N_G
Thanks for clarifying, I will check with our partners to see if they did the updates.
You should see this in the audit log.
 
  • Like
Reactions: N_G
@lancerichards That is what we are working on.....
It would be awesome if these patches can also be applied automatically when automatic updates on the PBX are disabled. On some of our larger systems the organization needs full control of changes.
 
  • Like
Reactions: Ecki and Evolute IT
It would be awesome if these patches can also be applied automatically when automatic updates on the PBX are disabled. On some of our larger systems the organization needs full control of changes.
For most organisations, it really depends on what their patch management / risk management looks like.
Years ago, it used to be the whole wait til patch Tuesday, have a sample set, then roll the next set, then a main deploy.
These days, with zero day, you just can't risk that anymore.

You need to look at the difference between what is going to be production impact vs a much bigger security risk. Waiting a week could be the difference between being breached or being patched.

I find that when it comes to CVE's and Sev 1, you need to make sure there is a good understanding of what that looks like for you and your customer and that your aligned in your way of managing risks :)
 
Status
Not open for further replies.

Forum statistics

Threads
111,818
Messages
589,166
Members
164,642
Latest member
davids86