Skip to content
HTTP/2 Bomb exploit chains compression and connection holds to crash web servers

HTTP/2 Bomb exploit chains compression and connection holds to crash web servers

Feeds.4Sysops IT News June 3, 2026

A newly discovered vulnerability called HTTP/2 Bomb allows remote attackers to crash major web servers by combining header compression exploits with connection-holding techniques. The attack targets the HPACK header compression scheme by sending thousands of tiny header entries that force the server to allocate significant memory for bookkeeping. By using a zero-byte flow-control window, the attacker prevents the server from ever releasing this allocated memory, effectively pinning it indefinitely. Source

Extracted Entities

Attack Types (1)

Vulnerabilities (1)