0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Remote Denial-of-Service Exploit HTTP/2 Bomb Affects Major Web Servers (blog.calif.io)

· 55d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Chains HPACK compression bomb and HTTP/2 window stall for memory exhaustion
  • Affects nginx, Apache, IIS, Envoy, Pingora on default configs
  • Single client can cause 32 GB memory consumption in seconds on some servers

"The HTTP/2 Bomb exploit chains a HPACK compression bomb with an HTTP/2 window stall to exhaust server memory. Affected servers include nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora on default configurations. A single client on a 100 Mbps connection can render a server inaccessible within seconds. Apache httpd and Envoy can be forced to consume 32 GB of memory in about 20 seconds by one client. The attack was discovered by the AI model Codex and disclosed by the Calif research team, along with mitigations and patches for some servers."

#HTTP/2 Bomb #HPACK compression exploit #Zero-byte window stall

Discussion Matrix

0 segments

no comments yet.