New HTTP/2 Vulnerability Lets Hackers Crash Servers With Memory Exhaustion Attacks
ID: af1957b6-c892-5786-bad5-29db47def414
STIX ID: report--af1957b6-c892-5786-bad5-29db47def414
Feed Name: cybersecurityNews.com
Threat Score
A newly disclosed HTTP/2 flow-control vulnerability enables unauthenticated remote attackers to stall outbound data (by manipulating SETTINGS_INITIAL_WINDOW_SIZE and withholding WINDOW_UPDATE frames), causing memory amplification and denial-of-service across multiple server implementations; several CVEs have been assigned and vendors are issuing patches and mitigations to limit buffered responses, concurrent streams, and stalled connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
