logo

HTTP/2 Bomb: How Default Configurations Open a New DoS Vector

ID: 0a0adc2e-db9b-593e-871f-154d7884423e

STIX ID: report--0a0adc2e-db9b-593e-871f-154d7884423e

Feed Name: SOCRadar Blog

Threat Score
72/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Ameer Owda

...
...

HTTP/2 Bomb is a remote Denial-of-Service chain that combines header-related allocation amplification and HTTP/2 flow-control connection holding to exhaust memory on servers running default HTTP/2 configurations; it affects widely deployed stacks (nginx, Apache httpd/mod_http2, IIS, Envoy, Pingora), PoC code exists, patches are incomplete, and defenders are advised to patch where available or mitigate by disabling HTTP/2, enforcing header-count and connection limits, and monitoring HTTP/2 metrics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.