CVE-2025-53020
CVSS 7.5 HIGH: late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP… EPSS 5% (91º percentile).
Vulnerabilità · 117 giorni fa
I principali front end HTTP/2 condividono una modalità di guasto che un client minuscolo può innescare rapidamente: la memoria cresce nella contabilizzazione degli header lato server, non nella request decodificata stessa, quindi i normali limiti di dimensione delle request non la intercettano. Un hold di flow-control a zero byte mantiene poi quella memoria bloccata fino a quando il servizio si arresta.
CVSS 7.5 HIGH: late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP… EPSS 5% (91º percentile).
4 fonti che coprono questa storia
Codex reunites researcher with a 14-year-old HTTP/2 blind spot
Researchers disclose an HTTP/2 denial-of-service technique affecting web servers including nginx and Apache after AI-assisted analysis uncovered a flaw linked to HTTP/2 configurations.
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds.
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
HTTP/2 Bomb exploits HPACK and flow control; a single client can hold 32GB memory in 20 seconds, causing server outages.
‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds
The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-05