logo

New HTTP/2 DoS attack can crash web servers with a single connection

ID: 05862607-76c2-593f-a2e2-02dbb5e747aa

STIX ID: report--05862607-76c2-593f-a2e2-02dbb5e747aa

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Newly discovered HTTP/2 "CONTINUATION Flood" vulnerabilities allow attackers to send a stream of CONTINUATION frames without the END_HEADERS flag, causing excessive memory consumption, CPU exhaustion, or out-of-memory crashes in multiple HTTP/2 implementations. CERT-CC published an alert mapping several CVEs affecting projects and vendors (Node.js, Envoy, Go, Apache, nghttp2, AMPHP, etc.); the researcher notes the issue can be triggered with as little as a single TCP connection, so affected servers should be patched and mitigations applied quickly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.