Back Feeds.4Sysops HTTP/2 Bomb exploit chains compression and connection holds to crash web servers
A newly discovered vulnerability called HTTP/2 Bomb allows remote attackers to crash major web servers by combining header compression exploits with connection-holding techniques. The attack targets the HPACK header compression scheme by sending thousands of tiny header entries that force the server to allocate significant memory for bookkeeping. By using a zero-byte flow-control window, the attacker prevents the server from ever releasing this allocated memory, effectively pinning it indefinitely. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
