Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CDN Tsunami Threat: HTTP/3 Amplification in Focus

CDN Tsunami Threat: HTTP/3 Amplification in Focus

Posted on August 20, 2026 By CWS

Recent research highlights two significant denial-of-service (DoS) vulnerabilities leveraging the conversion of HTTP/3 traffic to HTTP/1.1 by major content delivery networks (CDNs). Known as the ‘CDN Tsunami’ attacks, they can amplify minimal bandwidth requests by up to 350 times against the origin server.

Vulnerable CDNs and Attack Mechanisms

The study evaluated six key CDNs: Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent. It found all six vulnerable to the bandwidth amplification variant, while Cloudflare remained immune to the connection variant due to its specific request buffering method.

The attacks require HTTP/3 to be active on the CDN edge, with no modifications needed by the website itself. Notably, while HTTP/3 is advertised as available on Cloudflare by default, AWS documents suggest HTTP/2 as the default for new CloudFront setups.

The Mechanics of HTTP/3 Amplification

These attacks capitalize on the differences between HTTP/3 and HTTP/1.1. The QPACK dynamic table, used for compressing headers in HTTP/3, plays a crucial role. CDNs supporting this feature, like Alibaba, Baidu, and Tencent, can experience a dramatic 350x amplification. The amplification stems from transforming the compressed header indices into full headers for HTTP/1.1 requests.

The research indicates that bandwidth required by attackers stayed under 500 Kbps for CDNs with dynamic table support, while origin bandwidth consumption exceeded 100 Mbps. The attack effectiveness diminishes with more concurrent streams, likely due to increased CPU overhead at the CDN.

Mitigations and Industry Response

Proposed mitigations focus on limiting header sizes and references in the QPACK table and imposing restrictions on CDN-to-origin connections. Tencent has begun implementing these changes, while other vendors are still considering them.

The research, credited to several universities, will be presented at an upcoming symposium in 2026. No CVE identifiers have been assigned, and no real-world exploits have been reported. However, some vendors have already acknowledged the findings and are exploring solutions.

The findings underscore a shift in cyber threat dynamics, with amplification and reflection attacks becoming more prevalent, as highlighted in Cloudflare’s recent DDoS Threat Report.

The Hacker News Tags:Alibaba, Amazon CloudFront, Amplification Attack, Baidu, CDN Tsunami, CDN Vulnerabilities, Cloudflare, Cybersecurity, denial of service, Fastly, HTTP/3, Tencent

Post navigation

Previous Post: New Android Malware Manic Exploits Banking Security
Next Post: Hackers Exploit Microsoft 365 to Divert Payments

Related Posts

SysAid Flaws Under Active Attack Enable Remote File Access and SSRF SysAid Flaws Under Active Attack Enable Remote File Access and SSRF The Hacker News
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers The Hacker News
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware The Hacker News
Google Launches Android Developer Verification Initiative Google Launches Android Developer Verification Initiative The Hacker News
Update Your cPanel Server to Fix Critical Vulnerability Update Your cPanel Server to Fix Critical Vulnerability The Hacker News
Critical Flaw in Terrarium Sandbox Allows Code Execution Critical Flaw in Terrarium Sandbox Allows Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus
  • New Android Malware Manic Exploits Banking Security
  • Malicious Rust Crates Removed After Supply Chain Attack
  • Microsoft Defender Driver Exploitation Risks Uncovered

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus
  • New Android Malware Manic Exploits Banking Security
  • Malicious Rust Crates Removed After Supply Chain Attack
  • Microsoft Defender Driver Exploitation Risks Uncovered

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark