{"id":1135,"date":"2026-06-03T09:50:14","date_gmt":"2026-06-03T09:50:14","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1135"},"modified":"2026-06-03T09:50:14","modified_gmt":"2026-06-03T09:50:14","slug":"new-http-2-bomb-vulnerability-allows-remote-dos-on-nginx-apache-iis-envoy-cloudflare","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1135","title":{"rendered":"New HTTP\/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy &#038; Cloudflare"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 03, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Server Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhP07q0cgsa0a9VyTU6oPpxqvoZ5Gg2spx-ClmUIzn9LjYzDfuKNxnLXNuXMexiMB8GjKewhk7CnAL5HXgpCL_wq5eaU8VK2mTxxcKJHAZ9eLBskg516sBn4SV5XHWOuZIozDzBD_0MUCAMcVpGyqOEWITNKi2mQFxFLl9gqg_3UxPlwmXCkRfm2JERftyN\/s1700-e365\/http2.gif\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.<\/p>\n<p>The vulnerability has been codenamed <b><a href=\"https:\/\/blog.calif.io\/p\/codex-discovered-a-hidden-http2-bomb\">HTTP\/2 Bomb<\/a><\/b> by Calif.<\/p>\n<p>\u00abThe vulnerable behavior exists in each server&#8217;s default HTTP\/2 configuration,\u00bb the company said, adding it was discovered by OpenAI Codex by chaining together two known techniques: a compression bomb and a Slowloris-style hold.<\/p>\n<p>\u00abThe bomb targets HPACK, HTTP\/2&#8217;s header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request,\u00bb Calif added. \u00abThe hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p><a href=\"https:\/\/blog.cloudflare.com\/hpack-the-silent-killer-feature-of-http-2\/\">HPACK<\/a> is a dedicated header compression algorithm for HTTP\/2 used for compressing request and response metadata using Huffman encoding that results in an average reduction of 30% in header size. It&#8217;s also designed to be resilient to attacks like <a href=\"https:\/\/en.wikipedia.org\/wiki\/CRIME\">CRIME<\/a> (short for \u00abCompression Ratio Info-leak Made Easy\u00bb) that can leak authentication cookies from compressed headers.<\/p>\n<p>Slowloris, on the other hand, is a type of denial-of-service (DoS) attack that allows a threat actor to overwhelm a targeted server by opening and maintaining many simultaneous HTTP connections between the attacker and the target. It is an application-layer attack.<\/p>\n<p>HTTP\/2 Bomb is inspired by various known approaches like HPACK Bomb (aka <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-6581\">CVE-2016-6581<\/a>), which was first disclosed in 2016, as well as <a href=\"https:\/\/galbarnahum.com\/posts\/apache-httpd-cve-2025-53020\">CVE-2025-53020<\/a>, a memory exhaustion vulnerability in Apache httpd&#8217;s HTTP\/2 implementation, and two DoS flaws in Apache HTTP Server via crafted CONTINUATION frames (<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-8740\">CVE-2016-8740<\/a>) and worker-thread starvation (<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-1546\">CVE-2016-1546<\/a>) in an HTTP\/2 connection.<\/p>\n<p>\u00abWhat&#8217;s new here is where the amplification comes from,\u00bb Calif said. \u00abThe classic bomb stuffs a large value into the table and references it repeatedly, so servers learned to cap the total decoded header size. Our variant goes the other way: the header is nearly empty, and the amplification comes from the per-entry bookkeeping the server allocates around it. The decoded-size limit never fires because there&#8217;s almost nothing to decode.\u00bb<\/p>\n<p>In a hypothetical attack scenario, a home computer on a 100Mbps connection has the potential to render a vulnerable server inaccessible within seconds. What&#8217;s more, a single client can consume and hold 32GB of server memory against Apache HTTPD and Envoy in about 20 seconds.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>To counter the vulnerability, it&#8217;s advised to apply the following mitigations &#8211;<\/p>\n<ul>\n<li>NGINX &#8211; Upgrade to 1.29.8+, which adds the max_headers directive with a default of 1000. If upgrade is not an option, it&#8217;s recommended to disable HTTP\/2 with http2 off;.<\/li>\n<li>Apache HTTPD &#8211; Fixed in <a href=\"https:\/\/github.com\/icing\/mod_h2\/releases\">mod_http2 v2.0.41<\/a>. If upgrade is not an option, it&#8217;s recommended to set Protocols http\/1.1 to disable HTTP\/2.<\/li>\n<li>Microsoft IIS, Envoy, and Cloudflare Pingora &#8211; No patch available as of writing.<\/li>\n<\/ul>\n<p>\u00abThe deeper miss is that the spec frames memory risk purely as an amplification ratio, and ratio is only half the equation,\u00bb Calif said. \u00abA 70:1 amplifier is harmless if the memory is freed when the request completes. It becomes an attack because HTTP\/2 lets the client hold the connection open almost for free, pinning every allocated byte for as long as they like.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 03, 2026Vulnerability \/ Server Security Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1136,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1142,123,927,1532,1881,1530,1880,1230,12,68],"class_list":["post-1135","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-apache","tag-bomb","tag-cloudflare","tag-dos","tag-envoy","tag-http2","tag-iis","tag-nginx","tag-remote","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1135"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1135\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1136"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}