news.mlab.sh
Back to the feed
threat-intel

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

High
Image: The Hacker News
Summary

Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues for origin servers. The attacks, dubbed ‘CDN Tsunami,’ leverage a mismatch between CDN-supported HTTP/3 and origin server HTTP/1.1, resulting in up to 350x amplification. The vulnerabilities stem from a dynamic table used for HTTP/3 compression and a connection-based amplification technique. While vendors like Baidu and Tencent have deployed mitigations, the research highlights that these fixes are applied at the CDN level, not at the origin server. The study also identified a substantial number of potentially vulnerable subdomains hosted by the six CDNs examined.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.