Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New HTTP/2 Exploit Threatens Major Web Servers

New HTTP/2 Exploit Threatens Major Web Servers

Posted on June 3, 2026 By CWS

Security experts have identified a new exploit, known as the HTTP/2 Bomb, capable of swiftly disabling major web servers. This threat, revealed by Calif security researchers, combines known denial-of-service (DoS) techniques to impact thousands of websites.

Understanding the HTTP/2 Bomb Exploit

Discovered with the help of OpenAI’s Codex, the HTTP/2 Bomb utilizes a compression bomb targeting HTTP/2’s header compression scheme (HPACK) alongside a Slowloris-style attack. These techniques work together to prevent servers from releasing memory, causing them to crash.

The Calif-based cybersecurity firm warns that this exploit could affect over 880,000 websites using HTTP/2 with default configurations of NGINX, Apache HTTPD, Microsoft IIS, Envoy, or Cloudflare Pingora. Even a home computer with a 100 Mbps connection can launch an attack, rendering target servers unresponsive in seconds.

Technical Details of the Exploit

The HTTP/2 Bomb combines several previously known vulnerabilities. The first, identified as CVE-2016-6581, involves an HPACK Bomb. This attack uses small messages that expand significantly in size when processed by the server. Notably, last year an attack demonstrated against Apache HTTPD achieved a 4000x amplification rate. Apache resolved this in version 2.4.64 as CVE-2025-53020.

The second part exploits CVE-2016-8740 and CVE-2016-1546, targeting Apache HTTPD flaws to create DoS conditions via HTTP/2 request Continuation frames and altered flow-control windows. These tactics lead to memory exhaustion by minimizing server response and manipulating timeouts.

Current Responses and Future Implications

Calif notes that the novel aspect of this exploit is its amplification strategy. Unlike traditional methods, their variant utilizes minimal headers, increasing server load through bookkeeping processes. NGINX has patched this vulnerability as of April, while Apache issued fixes in May (CVE-2026-49975). However, Microsoft IIS, Envoy, and Cloudflare Pingora are still vulnerable.

The discovery process highlights the power of AI in cybersecurity. OpenAI’s Codex identified and combined the separate, decade-old vulnerabilities, resulting in this new threat. This underscores the need for continuous vigilance and innovation in cybersecurity measures.

For more on similar vulnerabilities, see related research on Flowise RCE, DirtyDecrypt Linux Kernel, and NGINX exploits.

Security Week News Tags:Apache, Calif research, Cloudflare Pingora, Cybersecurity, DoS attack, Envoy, HTTP/2, Microsoft IIS, NGINX, web server security

Post navigation

Previous Post: Unresolved Windows Search Vulnerability Risks NTLMv2 Hash Theft
Next Post: Windows URI Flaw Exposes NTLMv2 Hashes to Attackers

Related Posts

Black Hat USA 2025 – Summary of Vendor Announcements (Part 2) Black Hat USA 2025 – Summary of Vendor Announcements (Part 2) Security Week News
Hackers Exploit Ninja Forms Vulnerability on WordPress Hackers Exploit Ninja Forms Vulnerability on WordPress Security Week News
Portal26 Raises  Million for Gen-AI Adoption Platform Portal26 Raises $9 Million for Gen-AI Adoption Platform Security Week News
Fraud Prevention Firm Resistant AI Raises  Million Fraud Prevention Firm Resistant AI Raises $25 Million Security Week News
US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups Security Week News
Order out of Chaos – Using Chaos Theory Encryption to Protect OT and IoT Order out of Chaos – Using Chaos Theory Encryption to Protect OT and IoT Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security
  • AI Agent Security: Analysis of Top 100 and Key Findings

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security
  • AI Agent Security: Analysis of Top 100 and Key Findings

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark