Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CDN Tsunami Threat: HTTP/3 Amplification in Focus

CDN Tsunami Threat: HTTP/3 Amplification in Focus

Posted on August 20, 2026 By CWS

Recent research highlights two significant denial-of-service (DoS) vulnerabilities leveraging the conversion of HTTP/3 traffic to HTTP/1.1 by major content delivery networks (CDNs). Known as the ‘CDN Tsunami’ attacks, they can amplify minimal bandwidth requests by up to 350 times against the origin server.

Vulnerable CDNs and Attack Mechanisms

The study evaluated six key CDNs: Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent. It found all six vulnerable to the bandwidth amplification variant, while Cloudflare remained immune to the connection variant due to its specific request buffering method.

The attacks require HTTP/3 to be active on the CDN edge, with no modifications needed by the website itself. Notably, while HTTP/3 is advertised as available on Cloudflare by default, AWS documents suggest HTTP/2 as the default for new CloudFront setups.

The Mechanics of HTTP/3 Amplification

These attacks capitalize on the differences between HTTP/3 and HTTP/1.1. The QPACK dynamic table, used for compressing headers in HTTP/3, plays a crucial role. CDNs supporting this feature, like Alibaba, Baidu, and Tencent, can experience a dramatic 350x amplification. The amplification stems from transforming the compressed header indices into full headers for HTTP/1.1 requests.

The research indicates that bandwidth required by attackers stayed under 500 Kbps for CDNs with dynamic table support, while origin bandwidth consumption exceeded 100 Mbps. The attack effectiveness diminishes with more concurrent streams, likely due to increased CPU overhead at the CDN.

Mitigations and Industry Response

Proposed mitigations focus on limiting header sizes and references in the QPACK table and imposing restrictions on CDN-to-origin connections. Tencent has begun implementing these changes, while other vendors are still considering them.

The research, credited to several universities, will be presented at an upcoming symposium in 2026. No CVE identifiers have been assigned, and no real-world exploits have been reported. However, some vendors have already acknowledged the findings and are exploring solutions.

The findings underscore a shift in cyber threat dynamics, with amplification and reflection attacks becoming more prevalent, as highlighted in Cloudflare’s recent DDoS Threat Report.

The Hacker News Tags:Alibaba, Amazon CloudFront, Amplification Attack, Baidu, CDN Tsunami, CDN Vulnerabilities, Cloudflare, Cybersecurity, denial of service, Fastly, HTTP/3, Tencent

Post navigation

Previous Post: New Android Malware Manic Exploits Banking Security
Next Post: Hackers Exploit Microsoft 365 to Divert Payments

Related Posts

Why Organizations Are Abandoning Static Secrets for Managed Identities Why Organizations Are Abandoning Static Secrets for Managed Identities The Hacker News
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control The Hacker News
SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics The Hacker News
Discover Practical AI Tactics for GRC — Join the Free Expert Webinar Discover Practical AI Tactics for GRC — Join the Free Expert Webinar The Hacker News
Weekly Cybersecurity Update: Major Breaches and Vulnerabilities Weekly Cybersecurity Update: Major Breaches and Vulnerabilities The Hacker News
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Manic Malware Targets Android Devices with Innovative Techniques
  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus
  • New Android Malware Manic Exploits Banking Security
  • Malicious Rust Crates Removed After Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Manic Malware Targets Android Devices with Innovative Techniques
  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus
  • New Android Malware Manic Exploits Banking Security
  • Malicious Rust Crates Removed After Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark