CVE Tools

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

The Hacker NewsBy The Hacker News

ResearchCDN Services

Our summary

Security researchers have identified two denial-of-service vectors, collectively termed "CDN Tsunami," that exploit the conversion of HTTP/3 traffic to HTTP/1.1 by major content delivery networks. By leveraging mismatches in header compression and connection handling, attackers can amplify bandwidth or exhaust origin server connections, with factors reaching up to 350x on platforms like Alibaba, Baidu, and Tencent. Although no CVE has been assigned and no wild exploitation is currently reported, the study indicates significant potential for disruption across six prominent providers. Affected services include Cloudflare, Amazon CloudFront, and Fastly, prompting recommendations for stricter CDN-side limits on header sizes and backend connection multiplicity.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store