Skip to content

HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

Cybersecuritynews Guru Baran June 3, 2026

A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, enabling a single attacker on a internet connection to exhaust tens of gigabytes of server memory in seconds. The exploit was discovered by […]

Extracted Entities

Attack Types (1)

Companies (1)

Tools (1)