New ‘HTTP/2 Bomb’ Attack Can Cripple Web Servers in Seconds, Researchers Warn

At least nine Palestinians were killed after Israeli air strikes targeted residential buildings in Gaza City, according to local authorities and medical sources.

The newly discovered attack exploits weaknesses in the way web servers handle the HTTP/2 protocol, which is widely used across the internet to improve website performance and efficiency. Security experts warn that the attack affects default configurations of several leading server platforms, including NGINX, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare’s Pingora.

Unlike traditional distributed denial-of-service (DDoS) attacks that require large networks of compromised devices, HTTP/2 Bomb can achieve significant impact with minimal resources. This makes the technique particularly concerning for organizations relying on standard HTTP/2 deployments.

The vulnerability was uncovered by OpenAI’s Codex software agent working alongside researchers from offensive security firm Calif. Their findings revealed that the attack combines two previously known HTTP/2 abuse techniques into a more dangerous and effective method.

The first component leverages HPACK compression amplification, allowing attackers to force servers into excessive processing workloads. The second element uses a resource-retention strategy similar to the infamous Slowloris attack, exploiting HTTP/2 flow-control mechanisms to keep server resources occupied for extended periods.

By combining these methods, attackers can rapidly consume server memory and processing power, causing websites and online services to become unresponsive or crash entirely. Researchers noted that even well-provisioned systems may struggle to withstand the attack if left unpatched or configured with default settings.

The discovery highlights growing concerns about protocol-level attacks that exploit legitimate internet standards rather than relying on massive traffic volumes. Security teams are being urged to review their HTTP/2 configurations, apply available mitigations, and monitor systems for unusual connection behavior.

As cyber threats continue to evolve, the emergence of HTTP/2 Bomb serves as a reminder that even widely adopted internet technologies can become targets for innovative attack techniques capable of disrupting critical online infrastructure worldwide.

#CyberSecurity #CyberAttack #HTTP2Bomb #DoSAttack #DDoS #WebSecurity #InfoSec #CyberThreat #NGINX #Apache #MicrosoftIIS #Cloudflare #CyberNews #TechNews #DigitalSecurity #OpenAI #EthicalHacking #CyberDefense #OrionFeed #IrfanLatif

Irfan Latif

Irfan Latif