logo

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

ID: 80aa9c12-4f8f-5964-9a05-f93d380b8f04

STIX ID: report--80aa9c12-4f8f-5964-9a05-f93d380b8f04

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed “CDN Tsunami,” two HTTP/3-to-HTTP/1.1 amplification attacks (HBA and HCA) that let low-bandwidth clients amplify traffic up to ~350x against origin servers by exploiting CDNs that decompress or prematurely open backend connections when converting HTTP/3 to HTTP/1.1. Evaluated across six major CDNs (Alibaba, Baidu, Cloudflare, CloudFront, Fastly, Tencent), the study found broad exposure (42k+ potentially vulnerable HTTP/3 endpoints), measured amplification and connection impacts, and proposed CDN-side mitigations such as QPACK limits, request buffering, and connection caps; Baidu and Tencent deployed fixes while no CVEs or in-the-wild exploitation were reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.