Bleepingcomputer
New HTTP/2 Bomb DoS Attack Crashes Major Web Servers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack, identified by researchers at Calif and OpenAI's Codex, exploits the HPACK header compression mechanism and employs a zero-byte flow-control window to prevent memory from being released. A single attacker can exhaust tens of gigabytes of server memory in seconds, rendering the server inaccessible. Proof-of-concept exploits have been published, and while some platforms have released patches, many remain vulnerable. The full technical details will be presented at the Real World AI Security conference later this month.
Key Points: • HTTP/2 Bomb can crash major web servers in under a minute. • The attack combines HPACK compression amplification with connection-holding techniques. • Patches are available for some platforms, but many servers remain vulnerable.