threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and flow control techniques to overwhelm servers, and was identified by researchers using AI-powered code… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
ddos New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Researchers have identified a new HTTP/2 bomb vulnerability affecting web servers like NGINX, Apache, and IIS, allowing for remote denial-of-service attacks. The exploit leverages header compression and connection manage… The Hacker News · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740http2compressiondos