CDN Tsunami vulnerability enables 350x DoS amplification across major networks
Researchers have identified a new class of Denial-of-Service vulnerability called CDN Tsunami, which exploits protocol translation gaps between HTTP/3 and HTTP/1.1 to achieve up to 350x amplification. The flaw affects major CDN providers including Cloudflare, AWS CloudFront, and Fastly, potentially impacting over 42,000 subdomains by exhausting origin connection pools or abusing header compression.
Key Takeaways
- The vulnerability affects 42,330 confirmed HTTP/3-enabled subdomains across six major CDN providers.
- Attackers can use less than 500 Kbps of bandwidth to force an origin server to consume over 100 Mbps.
- Cloudflare is the only tested provider immune to the Connection Amplification variant due to its request buffering architecture.
- Baidu and Tencent have already deployed mitigations, while other vendors have acknowledged the flaw without immediate remediation.
Why It Matters
This vulnerability exposes a critical architectural weakness in how modern delivery networks bridge the gap between edge-side HTTP/3 and legacy origin-side HTTP/1.1. For streaming platforms, this means a low-bandwidth attacker can effectively take down origin servers by exploiting QPACK header compression or multiplexing features. As the industry shifts toward QUIC to improve video startup times, this flaw highlights the risks of heterogeneous protocol deployment. The lack of origin-side mitigations places the burden of security entirely on CDN providers to update their translation logic. Watch for other major CDNs to implement request buffering or QPACK table limits to close these amplification vectors.
Additional Context
The CDN Tsunami vulnerability arrives at a moment when HTTP/3 adoption is accelerating across the streaming and content delivery ecosystem. Cloudflare has been among the most aggressive proponents of QUIC and HTTP/3, having enabled HTTP/3 by default for all customer zones since 2023 and continuing to expand QUIC support across its edge network. Cloudflare reported that HTTP/3 now accounts for a growing share of total web traffic served through its network, with the protocol reducing connection establishment latency and improving performance on lossy mobile networks. Amazon CloudFront and Fastly have similarly rolled out HTTP/3 support at the edge, creating the exact heterogeneous protocol environments where translation-layer vulnerabilities emerge. The researchers behind the CDN Tsunami disclosure found that more than 42,000 subdomains across these providers exhibit exploitable translation gaps between HTTP/3 at the edge and HTTP/1.1 at the origin.
The business implications for CDN providers are significant given the competitive dynamics of the content delivery market. Fastly reported total revenue of $183.3 million in Q2 2026, up 23% year over year, with security revenue growing 43% and now representing 23% of total revenue, signaling that customers are increasingly bundling DDoS mitigation and security services with content delivery. A vulnerability that undermines confidence in protocol translation could accelerate demand for integrated security features, potentially benefiting providers that combine delivery with protection layers. Cloudflare, which has positioned its security suite as a differentiator against pure-play CDN competitors, stands to benefit from heightened awareness of edge-to-origin attack surfaces. The disclosure also lands as regulatory bodies in the EU and US have increased scrutiny of critical internet infrastructure resilience, with ENISA publishing updated guidance on CDN dependency risks for essential services in early 2026.
On the technical side, the CDN Tsunami findings build on a growing body of research into QUIC protocol security. Academic researchers published a systematic analysis of QUIC implementation vulnerabilities at the 2025 IEEE Symposium on Security and Privacy, identifying state machine inconsistencies across major QUIC implementations that parallel the translation gaps exploited in this disclosure. The QPACK header compression mechanism, which replaces HPACK from HTTP/2, introduces dynamic table state that can be manipulated when translation layers fail to properly synchronize compression contexts between protocol versions. Tencent and Alibaba, which operate large-scale CDN infrastructure serving Asian streaming platforms, have also deployed HTTP/3 at scale, though the researchers noted that their translation architectures differ from Western CDN providers in ways that may limit exposure to certain amplification vectors. The 350x amplification ratio reported in the CDN Tsunami research exceeds the typical 10-50x ratios seen in earlier HTTP/2 rapid reset attacks disclosed in 2023, representing a meaningful escalation in the threat landscape for origin infrastructure.
Read full article at rescana.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source