New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
News Source : Internet
News Summary
- A remote denial-of-service exploit affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
- The vulnerability has been codenamed HTTP/2 Bomb by Calif.
- In a hypothetical attack scenario, a home computer on a 100Mbps connection has the potential to render a vulnerable server inaccessible within seconds.
- To counter the vulnerability, it's advised to apply the following mitigations - "The deeper miss is that the spec frames memory risk purely as an amplification ratio, and ratio is only half the equation," Calif said.
Cybersecurity researchers have discovered a remote denialofservice exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
Never miss a story from us, subscribe to our newsletter