AI Stories on SHORT INFO are generated & curated with AI
unverified 04 Jun, 15:38

HTTP/2 Bomb flaw lets one laptop knock major web servers offline

Researchers at Calif disclosed HTTP/2 Bomb, a remote denial-of-service flaw in the default HTTP/2 configurations of NGINX, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single client can pin 32 GB of server memory against Apache and Envoy in about 20 seconds. Fixe

Calif disclosed HTTP/2 Bomb on June 3, 2026: a remote DoS exploit found by OpenAI Codex that chains HPACK compression amplification with a Slowloris-style zero-byte flow-control hold. One wire byte forces a full header allocation, thousands of times per request, and the held connection stops the server from freeing memory. A single client can pin 32 GB of server memory against Apache httpd and Envoy in about 20 seconds; a home computer on a 100 Mbps line can take a vulnerable server down within seconds. Affected in default config: NGINX, Apache httpd, Microsoft IIS, Envoy, Cloudflare Pingora. Mitigations: NGINX 1.29.8+ (max_headers), Apache mod_http2 v2.0.41; IIS, Envoy, and Pingora had no patch at disclosure - disable HTTP/2 or cap header counts. Source: The Hacker News, Calif research blog, oss-sec.

#cyber
Published on
TikTokFacebookYouTubeBlueskyThreadsInstagramX