vulnerability OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests A memory-exhaustion denial-of-service vulnerability, dubbed HollowByte, exists in OpenSSL versions 3.6.3, 3.5.7, 3.4.6, 3.0.21, 4.0.1, 3.6.2, and 3.6.3. The vulnerability stems from a flawed memory allocation process during TLS handshakes, where OpenSSL allocates a buffer size based on the client's claimed message leng… The Hacker News · Jul 17, 2026 High CVE-2025-66199CVE-2026-34183memory-exhaustiondostls
threat-intel New Enterprise-Ready MCP Specification Brings New Security Challenges The Model Context Protocol (MCP) is evolving from a single-user AI tool to an enterprise-ready platform designed for cloud-native AI usage, with a major update slated for July 28, 2026. This transition introduces new sec… SecurityWeek · Jun 26, 2026 High aistatelesssecurity
vulnerability Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Six vulnerabilities, dubbed Proto6, have been identified in protobuf.js, a JavaScript implementation of Protocol Buffers. These flaws could lead to remote code execution (RCE) and denial-of-service (DoS) attacks, primari… The Hacker News · Jun 10, 2026 High CVE-2026-44289CVE-2026-44290CVE-2026-44291node.jsprotobufrce
ddos New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute A new denial-of-service (DoS) attack, dubbed ‘HTTP/2 Bomb,’ has been identified that can cripple web servers within seconds by exploiting vulnerabilities in default HTTP/2 configurations of popular web servers like Nginx… BleepingComputer · Jun 3, 2026 High CVE-2026-49975doshttp2compression
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
ddos New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Researchers have identified a new HTTP/2 bomb vulnerability affecting web servers like NGINX, Apache, and IIS, allowing for remote denial-of-service attacks. The exploit leverages header compression and connection manage… The Hacker News · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740http2compressiondos
vulnerability ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) This advisory details a denial-of-service (DoS) vulnerability in ABB B&R Automation Runtime versions prior to 6.3 and Q4.93, specifically within the System Diagnostics Manager (SDM) component. An unauthenticated network… CISA Advisories · May 26, 2026 High CVE-2025-3450WOdosdenial of serviceresource locking