New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
ID: 1737e152-3033-5ea0-94d1-68c31ad388a4
STIX ID: report--1737e152-3033-5ea0-94d1-68c31ad388a4
Feed Name: Bleeping Computer
A new "HTTP/2 Bomb" DoS technique combines HPACK compression amplification and HTTP/2 flow-control stalling so a single client on a 100 Mbps link can exhaust tens of gigabytes of RAM on default configurations of major web servers (Envoy, Apache httpd, nginx, IIS) within seconds. PoC exploits exist and researchers report dramatic memory-amplification ratios (e.g., Envoy 5,700:1); patches/mitigations are available for some servers (nginx 1.29.8, Apache mod_http2 2.0.41 / CVE-2026-49975) while others (IIS, Envoy, Pingora) remained unpatched at time of writing—recommended mitigations include disabling HTTP/2 or placing proxies/WAFs that enforce header limits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
