logo

OpenAI's agent chained decade-old DoS attacks to crash web servers in seconds

ID: 9ab307c6-afee-5db7-9995-45119155d120

STIX ID: report--9ab307c6-afee-5db7-9995-45119155d120

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

...
...

## Executive summary A security researcher demonstrated an "HTTP/2 Bomb" DoS that composes a decade-old HPACK header-compression bomb with a Slowloris-style connection hold to quickly exhaust memory and crash major HTTP/2-capable servers (nginx, Apache, Envoy, Microsoft IIS, Cloudflare Pingora). Proof-of-concept exploits exist, some vendors have patched (nginx, Apache, Envoy mitigations reported) while others were still unpatched at disclosure; recommended mitigations include disabling HTTP/2 or capping header counts until fixes are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.