New HTTP/2 DoS attack can crash web servers with a single connection
ID: 05862607-76c2-593f-a2e2-02dbb5e747aa
STIX ID: report--05862607-76c2-593f-a2e2-02dbb5e747aa
Feed Name: Bleeping Computer
Newly discovered HTTP/2 "CONTINUATION Flood" vulnerabilities allow attackers to send a stream of CONTINUATION frames without the END_HEADERS flag, causing excessive memory consumption, CPU exhaustion, or out-of-memory crashes in multiple HTTP/2 implementations. CERT-CC published an alert mapping several CVEs affecting projects and vendors (Node.js, Envoy, Go, Apache, nghttp2, AMPHP, etc.); the researcher notes the issue can be triggered with as little as a single TCP connection, so affected servers should be patched and mitigations applied quickly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
