Close Menu
    What's Hot

    Nvidia’s RTX Spark Laptops Look Hell-Bent on Disruption

    In Portugal, Visitors are Flocking to Lisbon’s Food and Art Scenes

    Coursera now offers an AI-powered feed of short form educational content

    Facebook X (Twitter) Instagram
    Trending
    • Nvidia’s RTX Spark Laptops Look Hell-Bent on Disruption
    • In Portugal, Visitors are Flocking to Lisbon’s Food and Art Scenes
    • Coursera now offers an AI-powered feed of short form educational content
    • Opinion | America Broke Something When It Gave Trump a Second Chance
    • A Trump Endorsement Falls Flat: 4 Election Takeaways From Iowa and Beyond
    • Cease-Fires in Iran, Lebanon Matter Even After Collapse
    • Trump Aims New Tariffs at 59 Countries and the European Union
    • The world’s largest privately owned laser just turned on
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

    adminBy adminJune 3, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 03, 2026Vulnerability / Server Security

    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

    Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.

    The vulnerability has been codenamed HTTP/2 Bomb by Calif.

    “The vulnerable behavior exists in each server’s default HTTP/2 configuration,” the company said, adding it was discovered by OpenAI Codex by chaining together two known techniques: a compression bomb and a Slowloris-style hold.

    “The bomb targets HPACK, HTTP/2’s header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request,” Calif added. “The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.”

    Cybersecurity

    HPACK is a dedicated header compression algorithm for HTTP/2 used for compressing request and response metadata using Huffman encoding that results in an average reduction of 30% in header size. It’s also designed to be resilient to attacks like CRIME (short for “Compression Ratio Info-leak Made Easy”) that can leak authentication cookies from compressed headers.

    Slowloris, on the other hand, is a type of denial-of-service (DoS) attack that allows a threat actor to overwhelm a targeted server by opening and maintaining many simultaneous HTTP connections between the attacker and the target. It is an application-layer attack.

    HTTP/2 Bomb is inspired by various known approaches like HPACK Bomb (aka CVE-2016-6581), which was first disclosed in 2016, as well as CVE-2025-53020, a memory exhaustion vulnerability in Apache httpd’s HTTP/2 implementation, and two DoS flaws in Apache HTTP Server via crafted CONTINUATION frames (CVE-2016-8740) and worker-thread starvation (CVE-2016-1546) in an HTTP/2 connection.

    “What’s new here is where the amplification comes from,” Calif said. “The classic bomb stuffs a large value into the table and references it repeatedly, so servers learned to cap the total decoded header size. Our variant goes the other way: the header is nearly empty, and the amplification comes from the per-entry bookkeeping the server allocates around it. The decoded-size limit never fires because there’s almost nothing to decode.”

    In a hypothetical attack scenario, a home computer on a 100Mbps connection has the potential to render a vulnerable server inaccessible within seconds. What’s more, a single client can consume and hold 32GB of server memory against Apache HTTPD and Envoy in about 20 seconds.

    Cybersecurity

    To counter the vulnerability, it’s advised to apply the following mitigations –

    • NGINX – Upgrade to 1.29.8+, which adds the max_headers directive with a default of 1000. If upgrade is not an option, it’s recommended to disable HTTP/2 with http2 off;.
    • Apache HTTPD – Fixed in mod_http2 v2.0.41. If upgrade is not an option, it’s recommended to set Protocols http/1.1 to disable HTTP/2.
    • Microsoft IIS, Envoy, and Cloudflare Pingora – No patch available as of writing.

    “The deeper miss is that the spec frames memory risk purely as an amplification ratio, and ratio is only half the equation,” Calif said. “A 70:1 amplifier is harmless if the memory is freed when the request completes. It becomes an attack because HTTP/2 lets the client hold the connection open almost for free, pinning every allocated byte for as long as they like.”

    Apache Bomb Cloudflare Dos envoy HTTP2 IIs Nginx remote Vulnerability
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | California Got the Candidates It Deserves
    Next Article AI has a water problem. Google thinks it has a fix
    admin
    • Website

    Related Posts

    Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

    June 3, 2026

    Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

    June 2, 2026

    Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

    June 2, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Nvidia’s RTX Spark Laptops Look Hell-Bent on Disruption

    In Portugal, Visitors are Flocking to Lisbon’s Food and Art Scenes

    Coursera now offers an AI-powered feed of short form educational content

    Opinion | America Broke Something When It Gave Trump a Second Chance

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by