Skip to content
New HTTP/2 Bomb DoS Attack Crashes Major Web Servers

New HTTP/2 Bomb DoS Attack Crashes Major Web Servers

First seen 3 Jun 2026, 10:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 4, 2026 at 10:53 UTC
  • HTTP/2 Bomb can crash major web servers in under a minute.
  • The attack combines HPACK compression amplification with connection-holding techniques.
  • Patches are available for some platforms, but many servers remain vulnerable.

The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack, identified by researchers at Calif and OpenAI's Codex, exploits the HPACK header compression mechanism and employs a zero-byte flow-control window to prevent memory from being released. A single attacker can exhaust tens of gigabytes of server memory in seconds, rendering the server inaccessible. Proof-of-concept exploits have been published, and while some platforms have released patches, many remain vulnerable. The full technical details will be presented at the Real World AI Security conference later this month.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 98d ago How this analysis works

Timeline

2026-06-03
HTTP/2 Bomb attack disclosed
The HTTP/2 Bomb attack was revealed, impacting major web servers like NGINX and Apache, allowing memory exhaustion within seconds.
Bleepingcomputer
2026-06-03
Proof-of-concept exploits published
Researchers released proof-of-concept exploits for the HTTP/2 Bomb attack technique, demonstrating its effectiveness.
Gbhackers
2026-06-03
Technical details to be presented
Full technical details of the HTTP/2 Bomb attack will be disclosed at the Real World AI Security conference later this month.
Bleepingcomputer

More articles in this cluster (14)

Following this threat?

Track Envoy and CVE-2026-49975 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed