Continuation flood attack leading to issues on servers using HTTP/2.0
Details have emerged about the 'Continuation flood' attack method, which affects various implementations of the HTTP/2 protocol, including Apache httpd, Apache Traffic Server, Node.js, oghttp, Go net/http2, Envoy, oghttp, and nghttp2. This vulnerability can be exploited to carry out attacks on servers supporting HTTP/2.0, leading to memory exhaustion (cessation of request processing or crash of processes) depending on the implementation or […]
