logo

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

ID: 4659f1ba-1037-5679-a671-1307520df5f4

STIX ID: report--4659f1ba-1037-5679-a671-1307520df5f4

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed the "HTTP/2 Bomb," a remote DoS exploit that leverages HPACK header-compression amplification plus a zero-byte flow-control hold to pin large amounts of memory on HTTP/2 servers (NGINX, Apache HTTPD, Microsoft IIS, Envoy, Cloudflare Pingora). A single client can reportedly consume and hold tens of gigabytes (e.g., ~32GB against Apache/Envoy in ~20 seconds); patches or configuration mitigations exist for NGINX and Apache, while other vendors had no fixes at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.