HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk
This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a significant portion of internet infrastructure, particularly organizations utilizing web servers like nginx, Apache, and Microsoft IIS. While no major attacks have been observed yet, a publicly available proof-of-concept exists, highlighting the potential for exploitation. The vulnerability disproportionately impacts industries reliant on high-bandwidth internet services, such as telecommunications and healthcare.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
