{"id":181901,"date":"2026-06-05T02:48:08","date_gmt":"2026-06-05T00:48:08","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati"},"modified":"2026-06-05T02:48:08","modified_gmt":"2026-06-05T00:48:08","slug":"uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","title":{"rendered":"Schwachstelle HTTP\/2 Bomb, die zu einem Ersch\u00f6pfungsangriff auf den Speicher f\u00fchrt","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Anfang Juni 2026 entdeckten Cybersecurity-Forscher von Calif (mit Hilfe des KI-Agenten Codex) eine neue Variante des HTTP\/2 Bomb-Angriffs, der selbst mit einem einzigen Client-Ger\u00e4t funktioniert, das \u00fcber eine Internetverbindung mit 100 Mbit\/s verf\u00fcgt.<\/p>\n<p>Der Angriff besteht aus zwei Phasen:<\/p>\n<ol>\n<li>\n<p>Manipulation der HPACK-Kompression: Im HTTP\/2-Protokoll werden die Header mit Hilfe einer HPACK-Tabelle komprimiert. Der Angreifer sendet fast einen leeren Header, zwingt jedoch durch Hunderttausende von Anweisungen <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/server\/\" title=\"Server\" data-wpil-keyword-link=\"linked\">Server<\/a> dazu, ein und dasselbe winzige Element st\u00e4ndig zu entpacken und darauf zuzugreifen. Dies f\u00fchrt zu einem massiven Speicherverbrauch. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/server\/dts-los-angeles\/\" title=\"Server\" data-wpil-keyword-link=\"linked\">Server<\/a>.<\/p>\n<\/li>\n<li>\n<p>Blockierung des Flusskontrollmechanismus: Nachdem der Speicher gef\u00fcllt ist, setzt der Angreifer die Gr\u00f6\u00dfe des Flusskontrollfensters auf 0. Dies zwingt den Server, das Senden der Antwort zu pausieren, w\u00e4hrend der belegte Speicher gehalten wird, und die Verbindung durch gelegentliche 1-Byte-Anfragen offen zu halten.<\/p>\n<\/li>\n<\/ol>\n<p>Ein einziger Client kann innerhalb von 10\u201320 Sekunden bis zu 32\u201364 GB RAM verbrauchen. Der Speicherverbrauch variiert zwischen verschiedenen HTTP-Servern, von etwa 70 Byte pro Byte im Index f\u00fcr nginx, IIS und Pingora, bis zu 4000 Byte in Apache httpd und 5700 in Envoy.<\/p>\n<p>Fast alle Hauptimplementierungen von HTTP\/2 in den Standardkonfigurationen sind anf\u00e4llig:<br \/>\nNGINX, Apache HTTPD (modul mod_http2), Microsoft IIS, Envoy, Cloudflare, Pingora<\/p>\n<p>Die Schwachstelle wurde in nginx 1.29.8 (mit der max_headers-Direktive aus freenginx, die standardm\u00e4\u00dfig nicht mehr als 1000 Header verarbeitet), Envoy 1.35.11 und 1.36.7 (mutable_max_request_headers_kb und max_headers_count), und Apache mod_http2 2.0.41 behoben. F\u00fcr Microsoft IIS und Cloudflare Pingora gibt es derzeit noch keine Patches.<\/p>\n<p>Der HTTP-Server Angie ist nicht betroffen, da er bereits in Version 1.8.0, die 2024 ver\u00f6ffentlicht wurde, Schutzma\u00dfnahmen gegen derartige Angriffe implementiert hat.<\/p>\n<p>Quelle: <a rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18311265\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0441\u043e \u0441\u043a\u043e\u0440\u043e\u0441\u0442\u044c\u044e 100 \u041c\u0431\u0438\u0442\/\u0441. \u0410\u0442\u0430\u043a\u0430 \u0441\u043e\u0441\u0442\u043e\u0438\u0442 \u0438\u0437 \u0434\u0432\u0443\u0445 \u044d\u0442\u0430\u043f\u043e\u0432: \u041c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u044f \u0441\u0436\u0430\u0442\u0438\u0435\u043c HPACK: \u0412 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 HTTP\/2 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0438 \u0441\u0436\u0438\u043c\u0430\u044e\u0442\u0441\u044f \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0430\u0431\u043b\u0438\u0446\u044b HPACK. \u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u043f\u043e\u0447\u0442\u0438 \u043f\u0443\u0441\u0442\u043e\u0439 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181901","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c HTTP\/2 Bomb, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044e \u043e\u043f\u0435\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-05T00:48:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-05T00:48:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Die HTTP\/2 Bomb-Schwachstelle f\u00fchrt zu einem Speicherverbrauch | ProHoster","description":"Anfang Juni 2026 entdeckten Cybersecurity-Forscher von Calif (mit Hilfe des KI-Agenten Codex) eine neue Variante des HTTP\/2 Bomb-Angriffs, der selbst mit einem einzigen Client-Ger\u00e4t funktioniert.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c HTTP\/2 Bomb, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044e \u043e\u043f\u0435\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 | ProHoster","og:description":"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-05T00:48:08+00:00","article:modified_time":"2026-06-05T00:48:08+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/181901","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=181901"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/181901\/revisions"}],"predecessor-version":[{"id":182083,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/181901\/revisions\/182083"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=181901"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=181901"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=181901"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}