New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Researchers have identified a new HTTP/2 bomb vulnerability affecting web servers like NGINX, Apache, and IIS, allowing for remote denial-of-service attacks. The exploit leverages header compression and connection management to exhaust server resources, potentially causing significant disruption. The vulnerability highlights the importance of proper configuration and timely patching to mitigate these risks.
A cybersecurity research firm, Calif, discovered a remote denial-of-service (DoS) vulnerability dubbed the "HTTP/2 Bomb" targeting major web servers including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability stems from a combination of a compression bomb and a Slowloris-style hold attack, exploiting the HPACK header compression scheme used in HTTP/2. This allows an attacker to trigger excessive header allocations, overwhelming the server's memory and processing capabilities. The attack is amplified by the server's handling of the compressed headers, leading to a rapid consumption of resources.
