THE content discusses a newly disclosed HTTP/2 Denial of Service (DoS) vulnerability affecting multiple server implementations. The vulnerability allows remote, unauthenticated attackers to crash or freeze servers by exploiting flow control settings. This issue enables attackers to drain server memory through stalled data buffering, impacting high levels of web traffic managed by HTTP/2. Key affected products include F5 BIG-IP and Apache Traffic Server, each with specific CVEs and severity ratings.
Mitigation steps involve updating to fixed versions, configuration hardening, and quickly terminating stalled connections. No public exploitation has been reported, but prompt patching is advised.