Switch language한국어
Back to the list

CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks

TL;DR AI

Key summary

1 min read
  1. Researchers found a new DoS risk in CDNs that convert HTTP/3 traffic to HTTP/1.1.

  2. The paper describes two attack modes: bandwidth amplification and connection amplification.

  3. A scan of the Tranco Top 1M found 42,330 potentially vulnerable subdomains.

  4. The issue was disclosed to vendors, and some confirmed the bug and shipped mitigations.

Read the original