<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>DoS on kalfaoglu.net</title><link>https://blog.kalfaoglu.net/tags/dos/</link><description>Recent content in DoS on kalfaoglu.net</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 04 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.kalfaoglu.net/tags/dos/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-49975: The HTTP/2 Bomb That Knocks nginx and Apache Offline With a Single Connection</title><link>https://blog.kalfaoglu.net/posts/2026-06-04-cve-2026-49975-http2-bomb-en/</link><pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog.kalfaoglu.net/posts/2026-06-04-cve-2026-49975-http2-bomb-en/</guid><description>&lt;p&gt;On June 3, 2026, researcher Quang Luong published a remote denial-of-service exploit called the &lt;a href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb"&gt;HTTP/2 Bomb&lt;/a&gt; that can exhaust tens of gigabytes of server memory using nothing more than a home internet connection. The vulnerability was &lt;a href="https://seclists.org/oss-sec/2026/q2/790"&gt;posted to oss-security&lt;/a&gt; the same day and affects nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora in their default HTTP/2 configurations.&lt;/p&gt;
&lt;p&gt;The CVE identifier CVE-2026-49975 was assigned to the Apache httpd variant.&lt;/p&gt;
&lt;h2 id="what-the-attack-does"&gt;What the attack does&lt;/h2&gt;
&lt;p&gt;The exploit chains two techniques, both of which have been individually documented for roughly a decade, in a way that no prior public research had combined against these servers.&lt;/p&gt;</description></item></channel></rss>