securityonline.info 7/23/2026, 4:31:28 PM · external

HTTP/2 DoS bug puts F5 BIG IP and Apache Traffic Server at risk

HTTP/2 DoS bug puts F5 BIG IP and Apache Traffic Server at risk
CyberSIXT Evidence Panel
Primary Source kb.cert.org

THE content discusses a newly disclosed HTTP/2 Denial of Service (DoS) vulnerability affecting multiple server implementations. The vulnerability allows remote, unauthenticated attackers to crash or freeze servers by exploiting flow control settings. This issue enables attackers to drain server memory through stalled data buffering, impacting high levels of web traffic managed by HTTP/2. Key affected products include F5 BIG-IP and Apache Traffic Server, each with specific CVEs and severity ratings.

Mitigation steps involve updating to fixed versions, configuration hardening, and quickly terminating stalled connections. No public exploitation has been reported, but prompt patching is advised.

View Primary Source Via securityonline.info

Article by CyberSIXT