logo

New HTTP/2 Vulnerability Exposes Web Servers to DoS Attacks

ID: 61a18295-e0a2-50c9-bf6f-6fc66f506d9e

STIX ID: report--61a18295-e0a2-50c9-bf6f-6fc66f506d9e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** New research disclosed the "HTTP/2 CONTINUATION Flood" vulnerability where improperly handled CONTINUATION frames in HTTP/2 can be used to create never-ending header streams that exhaust memory or CPU, causing crashes and denial-of-service across numerous widely used implementations (Apache HTTPD, Tomcat, Envoy, Golang, Node.js, nghttp2, etc.); multiple CVEs are listed and users are advised to upgrade or disable HTTP/2 until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.