New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Image for article New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
News Source : Internet

News Summary

  • A remote denial-of-service exploit affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
  • The vulnerability has been codenamed HTTP/2 Bomb by Calif.
  • In a hypothetical attack scenario, a home computer on a 100Mbps connection has the potential to render a vulnerable server inaccessible within seconds.
  • To counter the vulnerability, it's advised to apply the following mitigations - "The deeper miss is that the spec frames memory risk purely as an amplification ratio, and ratio is only half the equation," Calif said.
Cybersecurity researchers have discovered a remote denialofservice exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.

Must read Articles