A new denial-of-service exploit, dubbed 'HTTP/2 Bomb,' targets default HTTP/2 configurations in major web servers like nginx, Apache, IIS, Envoy, and Cloudflare Pingora. The exploit chains an HPACK compression bomb with a Slowloris-style connection hold to rapidly exhaust server memory, even from a basic internet connection. This development poses a significant threat to web infrastructure, requiring developers and system administrators to promptly apply patches or implement mitigation strategies to protect against memory exhaustion attacks.
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





