{"id":181901,"date":"2026-06-05T02:48:08","date_gmt":"2026-06-05T00:48:08","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati"},"modified":"2026-06-05T02:48:08","modified_gmt":"2026-06-05T00:48:08","slug":"uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","title":{"rendered":"Vulnerabilidad HTTP\/2 Bomb que lleva al agotamiento de la memoria","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A principios de junio de 2026, los investigadores en ciberseguridad de la empresa Calif (con la ayuda del agente de IA Codex) descubrieron una nueva variante del ataque HTTP\/2 Bomb, que funciona incluso desde un solo dispositivo cliente con una conexi\u00f3n a Internet de 100 Mbps.<\/p>\n<p>El ataque consta de dos etapas:<\/p>\n<ol>\n<li>\n<p>Manipulaci\u00f3n de la compresi\u00f3n HPACK: En el protocolo HTTP\/2, las cabeceras se comprimen utilizando una tabla HPACK. El atacante env\u00eda una cabecera casi vac\u00eda, pero con cientos de miles de instrucciones obliga <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/\" title=\"servidor\" data-wpil-keyword-link=\"linked\">servidor<\/a> a descomprimir y referirse constantemente al mismo peque\u00f1o elemento. Esto provoca un gasto de memoria en avalancha. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-los-angeles\/\" title=\"servidores\" data-wpil-keyword-link=\"linked\">servidores<\/a>.<\/p>\n<\/li>\n<li>\n<p>Bloqueo del flujo de control: Una vez que la memoria est\u00e1 llena, el atacante establece el tama\u00f1o de la ventana de control del flujo en 0. Esto hace que el servidor pause el env\u00edo de la respuesta, manteniendo la memoria ocupada y manteniendo la conexi\u00f3n abierta con solicitudes peri\u00f3dicas de 1 byte.<\/p>\n<\/li>\n<\/ol>\n<p>Un solo cliente puede consumir hasta 32-64 GB de memoria RAM en 10-20 segundos. El nivel de consumo de memoria en varios servidores HTTP var\u00eda desde aproximadamente 70 bytes por cada byte en el \u00edndice para nginx, IIS y Pingora, hasta 4000 bytes en Apache httpd y 5700 en Envoy.<\/p>\n<p>Pr\u00e1cticamente todas las principales implementaciones de servidor HTTP\/2 en configuraciones por defecto son vulnerables:<br \/>\nNGINX, Apache HTTPD (m\u00f3dulo mod_http2), Microsoft IIS, Envoy, Cloudflare, Pingora.<\/p>\n<p>La vulnerabilidad ha sido corregida en nginx 1.29.8 (con la directiva max_headers de freenginx, que por defecto permite procesar no m\u00e1s de 1000 cabeceras), Envoy 1.35.11 y 1.36.7 (mutable_max_request_headers_kb y max_headers_count), Apache mod_http2 2.0.41. Actualmente, no hay correcciones para Microsoft IIS y Cloudflare Pingora.<\/p>\n<p>El servidor HTTP Angie no es vulnerable, ya que implement\u00f3 protecciones contra este tipo de ataques ya en la versi\u00f3n 1.8.0, lanzada en 2024.<\/p>\n<p>Fuente: <a rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18311265\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0441\u043e \u0441\u043a\u043e\u0440\u043e\u0441\u0442\u044c\u044e 100 \u041c\u0431\u0438\u0442\/\u0441. \u0410\u0442\u0430\u043a\u0430 \u0441\u043e\u0441\u0442\u043e\u0438\u0442 \u0438\u0437 \u0434\u0432\u0443\u0445 \u044d\u0442\u0430\u043f\u043e\u0432: \u041c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u044f \u0441\u0436\u0430\u0442\u0438\u0435\u043c HPACK: \u0412 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 HTTP\/2 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0438 \u0441\u0436\u0438\u043c\u0430\u044e\u0442\u0441\u044f \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0430\u0431\u043b\u0438\u0446\u044b HPACK. \u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u043f\u043e\u0447\u0442\u0438 \u043f\u0443\u0441\u0442\u043e\u0439 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181901","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c HTTP\/2 Bomb, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044e \u043e\u043f\u0435\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-05T00:48:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-05T00:48:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilidad HTTP\/2 Bomb que conduce a la agotamiento de la memoria RAM | ProHoster","description":"A principios de junio de 2026, los investigadores en ciberseguridad de la empresa Calif (con la ayuda del agente de IA Codex) descubrieron una nueva variante del ataque HTTP\/2 Bomb, que funciona incluso desde un solo dispositivo cliente con.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c HTTP\/2 Bomb, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044e \u043e\u043f\u0435\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 | ProHoster","og:description":"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u0438\u044e\u043d\u044f 2026 \u0433\u043e\u0434\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Calif (\u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0418\u0418-\u0430\u0433\u0435\u043d\u0442\u0430 Codex) \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 HTTP\/2 Bomb, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0434\u0430\u0436\u0435 \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-http-2-bomb-privodyashhaya-k-ischerpaniyu-operativnoj-pamyati","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-05T00:48:08+00:00","article:modified_time":"2026-06-05T00:48:08+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181901","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=181901"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181901\/revisions"}],"predecessor-version":[{"id":182083,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181901\/revisions\/182083"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=181901"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=181901"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=181901"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}