New HTTP/2 Bomb DoS Attack Crashes Major Web Servers

New HTTP/2 Bomb DoS Attack Crashes Major Web Servers

First seen 3 Jun 2026, 10:56 UTC CybersecuritynewsGbhackersBleepingcomputerFeeds.4SysopsCsoonline+7 89% similarity 69.0

Article Content

Browse articles
ThreatCluster

The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack, identified by researchers at Calif and OpenAI's Codex, exploits the HPACK header compression mechanism and employs a zero-byte flow-control window to prevent memory from being released. A single attacker can exhaust tens of gigabytes of server memory in seconds, rendering the server inaccessible. Proof-of-concept exploits have been published, and while some platforms have released patches, many remain vulnerable. The full technical details will be presented at the Real World AI Security conference later this month.

Key Points: • HTTP/2 Bomb can crash major web servers in under a minute. • The attack combines HPACK compression amplification with connection-holding techniques. • Patches are available for some platforms, but many servers remain vulnerable.

ThreatCluster AI

Timeline

2026-06-03
HTTP/2 Bomb attack disclosed
The HTTP/2 Bomb attack was revealed, impacting major web servers like NGINX and Apache, allowing memory exhaustion within seconds.
Bleepingcomputer
2026-06-03
Proof-of-concept exploits published
Researchers released proof-of-concept exploits for the HTTP/2 Bomb attack technique, demonstrating its effectiveness.
Gbhackers
2026-06-03
Technical details to be presented
Full technical details of the HTTP/2 Bomb attack will be disclosed at the Real World AI Security conference later this month.
Bleepingcomputer

Community

Browse all →