HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk
This article details the "HTTP/2 Bomb" vulnerability (CVE-2026-49975), a high-severity denial-of-service (DoS) exploit discovered via AI that chains together two HTTP/2 features—HPACK header compression and flow control—to create massive amplification attacks. An attacker with minimal resources can overwhelm vulnerable servers (including nginx, Apache, Envoy, and Microsoft IIS) by sending small requests that force the server to expand memory usage while blocking responses. While patches are available from most vendors, over 880,000 websites remain potentially vulnerable. The exploit disproportionately impacts industries with large web footprints, particularly telecommunications (25% of vulnerable servers), IT (18%), and healthcare (17%). Organizations are urged to patch immediately to mitigate the risk.
https://www.darkreading.com/vulnerabilities-threats/http-2-bomb-attacks-telcos-healthcare
Comments
Post a Comment