New HTTP/2 Vulnerability Exposes Web Servers to DoS Attacks
ID: 61a18295-e0a2-50c9-bf6f-6fc66f506d9e
STIX ID: report--61a18295-e0a2-50c9-bf6f-6fc66f506d9e
Feed Name: The Hacker News
Threat Score
**Executive summary:** New research disclosed the "HTTP/2 CONTINUATION Flood" vulnerability where improperly handled CONTINUATION frames in HTTP/2 can be used to create never-ending header streams that exhaust memory or CPU, causing crashes and denial-of-service across numerous widely used implementations (Apache HTTPD, Tomcat, Envoy, Golang, Node.js, nghttp2, etc.); multiple CVEs are listed and users are advised to upgrade or disable HTTP/2 until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
