Website Security & Threat Management
HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks

HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks

10/10/2023 · Grant Bourzikas

What this post added

This post details Cloudflare's response to a novel zero-day vulnerability in the HTTP/2 protocol, dubbed 'HTTP/2 Rapid Reset'. It describes how the vulnerability was exploited to generate hyper-volumetric DDoS attacks, including an attack exceeding 201 million requests per second. Cloudflare mitigated these attacks by developing purpose-built technology and collaborating with industry partners for responsible disclosure and patching. The post also provides recommendations for CSOs on how to protect their organizations.

Read the original post ↗