logo

New HTTP/2 Vulnerability Lets Hackers Crash Servers With Memory Exhaustion Attacks

ID: af1957b6-c892-5786-bad5-29db47def414

STIX ID: report--af1957b6-c892-5786-bad5-29db47def414

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Abinaya

...
...

A newly disclosed HTTP/2 flow-control vulnerability enables unauthenticated remote attackers to stall outbound data (by manipulating SETTINGS_INITIAL_WINDOW_SIZE and withholding WINDOW_UPDATE frames), causing memory amplification and denial-of-service across multiple server implementations; several CVEs have been assigned and vendors are issuing patches and mitigations to limit buffered responses, concurrent streams, and stalled connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.