Codex Discovered a Hidden HTTP/2 Bomb (opens in new tab)
We’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, including:nginxApache httpdMicrosoft IISEnvoyCloudflare PingoraThe vulnerable behavior exists in each server's default HTTP/2 configuration.The attack was discovered by Codex, which chained two techniques known to humans for a decade: a compression bomb and a Slowloris-style hold. The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on...
Read the original article