Rescana CDN Tsunami: New HTTP/3 to HTTP/1.1 DoS Attack Amplifies Traffic Significantly
Article Content
- •CDN Tsunami attacks exploit the gap between HTTP/3 and HTTP/1.1 protocols.
- •Amplification factors can reach up to 350x, affecting major CDN providers.
- •Two attack variants, HBA and HCA, target bandwidth and connection exhaustion.
A new class of Denial-of-Service (DoS) attacks, termed CDN Tsunami, exploits the protocol translation gap between HTTP/3 at the CDN edge and HTTP/1.1 to the origin server. This vulnerability affects six major CDN providers, including Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent. Attackers can amplify small HTTP/3 traffic into massive HTTP/1.1 requests, achieving amplification factors of up to 350x. Two attack variants have been identified: HTTP/3 Bandwidth Amplification (HBA) and HTTP/3 Connection Amplification (HCA). Over 42,000 subdomains in the Tranco Top 1M are potentially vulnerable. As of August 2026, no CVE has been assigned, and no exploitation in the wild has been reported. Mitigations have been deployed by Baidu and Tencent, while other vendors have acknowledged the issue but have not yet remediated. The root cause is the heterogeneous protocol deployment in CDNs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Alibaba in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…