CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues for origin servers. The attacks, dubbed ‘CDN Tsunami,’ leverage a mismatch between CDN-supported HTTP/3 and origin server HTTP/1.1, resulting in up to 350x amplification. The vulnerabilities stem from a dynamic table used for HTTP/3 compression and a connection-based amplification technique. While vendors like Baidu and Tencent have deployed mitigations, the research highlights that these fixes are applied at the CDN level, not at the origin server. The study also identified a substantial number of potentially vulnerable subdomains hosted by the six CDNs examined.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
