CVE-2025-53020
CVSS 7.5 HIGH: late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP… EPSS 5% (91º percentile).
Vulnerabilità ed exploit
I principali front end HTTP/2 condividono una modalità di guasto che un client minuscolo può innescare rapidamente: la memoria cresce nella contabilizzazione degli header lato server, non nella request decodificata stessa, quindi i normali limiti di dimensione delle request non la intercettano. Un hold di flow-control a zero byte mantiene poi quella memoria bloccata fino a quando il servizio si arresta.
4 fonti · 4 giu
CVSS 7.5 HIGH: late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP… EPSS 5% (91º percentile).
CSO Online
Codex reunites researcher with a 14-year-old HTTP/2 blind spot
Researchers disclose an HTTP/2 denial-of-service technique affecting web servers including nginx and Apache after AI-assisted analysis uncovered a flaw linked to HTTP/2 configurations.
originaleBleepingComputer
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds.
originaleThe Hacker News
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
HTTP/2 Bomb exploits HPACK and flow control; a single client can hold 32GB memory in 20 seconds, causing server outages.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-05
Every edition of this story: I default di HTTP/2 condividono un percorso rapido di esaurimento della memoria