HTTP/2 Bomb: How Default Configurations Open a New DoS Vector
ID: 0a0adc2e-db9b-593e-871f-154d7884423e
STIX ID: report--0a0adc2e-db9b-593e-871f-154d7884423e
Feed Name: SOCRadar Blog
HTTP/2 Bomb is a remote Denial-of-Service chain that combines header-related allocation amplification and HTTP/2 flow-control connection holding to exhaust memory on servers running default HTTP/2 configurations; it affects widely deployed stacks (nginx, Apache httpd/mod_http2, IIS, Envoy, Pingora), PoC code exists, patches are incomplete, and defenders are advised to patch where available or mitigate by disabling HTTP/2, enforcing header-count and connection limits, and monitoring HTTP/2 metrics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
