SECURITYTHE HACKER NEWS
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Cybersecurity researchers discovered a remote denial-of-service vulnerability, HTTP/2 Bomb, affecting major web servers including NGINX, Apache, IIS, Envoy, and Cloudflare. The exploit exists in default HTTP/2 configurations and was found by OpenAI Codex through chaining.
Mentioned