HTTP/2 Bomb Exploit Crashes Major Web Servers Remotely
A newly disclosed HTTP/2 vulnerability dubbed “HTTP/2 Bomb” enables attackers to trigger severe resource exhaustion on major web servers including nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora through a single malicious request. The attack leverages HTTP/2’s HPACK header compress