Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CDN Tsunami Threat: HTTP/3 Amplification in Focus

CDN Tsunami Threat: HTTP/3 Amplification in Focus

Posted on August 20, 2026 By CWS

Recent research highlights two significant denial-of-service (DoS) vulnerabilities leveraging the conversion of HTTP/3 traffic to HTTP/1.1 by major content delivery networks (CDNs). Known as the ‘CDN Tsunami’ attacks, they can amplify minimal bandwidth requests by up to 350 times against the origin server.

Vulnerable CDNs and Attack Mechanisms

The study evaluated six key CDNs: Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent. It found all six vulnerable to the bandwidth amplification variant, while Cloudflare remained immune to the connection variant due to its specific request buffering method.

The attacks require HTTP/3 to be active on the CDN edge, with no modifications needed by the website itself. Notably, while HTTP/3 is advertised as available on Cloudflare by default, AWS documents suggest HTTP/2 as the default for new CloudFront setups.

The Mechanics of HTTP/3 Amplification

These attacks capitalize on the differences between HTTP/3 and HTTP/1.1. The QPACK dynamic table, used for compressing headers in HTTP/3, plays a crucial role. CDNs supporting this feature, like Alibaba, Baidu, and Tencent, can experience a dramatic 350x amplification. The amplification stems from transforming the compressed header indices into full headers for HTTP/1.1 requests.

The research indicates that bandwidth required by attackers stayed under 500 Kbps for CDNs with dynamic table support, while origin bandwidth consumption exceeded 100 Mbps. The attack effectiveness diminishes with more concurrent streams, likely due to increased CPU overhead at the CDN.

Mitigations and Industry Response

Proposed mitigations focus on limiting header sizes and references in the QPACK table and imposing restrictions on CDN-to-origin connections. Tencent has begun implementing these changes, while other vendors are still considering them.

The research, credited to several universities, will be presented at an upcoming symposium in 2026. No CVE identifiers have been assigned, and no real-world exploits have been reported. However, some vendors have already acknowledged the findings and are exploring solutions.

The findings underscore a shift in cyber threat dynamics, with amplification and reflection attacks becoming more prevalent, as highlighted in Cloudflare’s recent DDoS Threat Report.

The Hacker News Tags:Alibaba, Amazon CloudFront, Amplification Attack, Baidu, CDN Tsunami, CDN Vulnerabilities, Cloudflare, Cybersecurity, denial of service, Fastly, HTTP/3, Tencent

Post navigation

Previous Post: New Android Malware Manic Exploits Banking Security
Next Post: Hackers Exploit Microsoft 365 to Divert Payments

Related Posts

What the Next Wave of AI Cyberattacks Will Look Like — And How to Survive What the Next Wave of AI Cyberattacks Will Look Like — And How to Survive The Hacker News
Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play The Hacker News
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts The Hacker News
U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing 0K Crypto Transfers and M+ Profits U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits The Hacker News
INTERPOL’s Cybercrime Crackdown Nets 651 Arrests in Africa INTERPOL’s Cybercrime Crackdown Nets 651 Arrests in Africa The Hacker News
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Citrix NetScaler Vulnerability Exploited in Ongoing Attacks
  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Citrix NetScaler Vulnerability Exploited in Ongoing Attacks
  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark