{"id":238302,"date":"2026-06-04T02:25:33","date_gmt":"2026-06-04T07:25:33","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/06\/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute"},"modified":"2026-06-04T02:25:33","modified_gmt":"2026-06-04T07:25:33","slug":"new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/06\/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute","title":{"rendered":"New \u2018HTTP\/2 Bomb\u2019 DoS attack crashes web servers in under a minute"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute.jpg\"><\/a><\/p>\n<p>A new denial-of-service (DoS) attack dubbed HTTP\/2 Bomb can be launched from a single machine to take down web servers within seconds.<\/p>\n<p>The technique works on default HTTP\/2 configurations of major web servers, including NGINX, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora.<\/p>\n<p>Discovered by OpenAI\u2019s Codex software agent under the guidance of researchers at offensive security firm Calif, HTTP\/2 Bomb combines two previously known HTTP\/2 DoS methods: the HPACK compression amplification and Slowloris-style resource retention via HTTP\/2 flow-control stalling.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new denial-of-service (DoS) attack dubbed HTTP\/2 Bomb can be launched from a single machine to take down web servers within seconds. The technique works on default HTTP\/2 configurations of major web servers, including NGINX, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora. Discovered by OpenAI\u2019s Codex software agent under the guidance of researchers [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,1492],"tags":[],"class_list":["post-238302","post","type-post","status-publish","format-standard","hentry","category-robotics-ai","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/238302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=238302"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/238302\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=238302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=238302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=238302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}