Microsoft Windows HTTP.sys Header Parsing Remote DoS (CVE-2026-47291)

This module sends a crafted HTTP/1.1 request over TLS to a service backed by the Windows HTTP Protocol Stack driver, HTTP.sys. The request contains a large number of compact headers. The exploit uses LINE mode, sending each complete HTTP line in a separate TLS application-data write to align with the ZDI trigger mechanics and accumulate HTTP.sys buffer references.
Exploit Platform
Exploit Type
Product Name