HTTP/2 Bomb: OpenAI's Codex uncovers critical DoS risk for streaming infrastructure
OpenAI's Codex AI assisted in discovering CVE-2023-44487, an HTTP/2 denial-of-service vulnerability dubbed an "HTTP/2 Bomb," which can crash web servers by consuming over 30GB of RAM within seconds. Major providers including Amazon, Cloudflare, Google, and Microsoft have released patches, necessitating immediate updates for streaming service infrastructure. This poses a critical security risk for streaming providers relying on HTTP/2 for content delivery.
Key Takeaways
- The 'HTTP/2 Bomb' (CVE-2023-44487) exploits HTTP/2 frame streams, forcing servers to consume over 30GB of RAM rapidly.
- OpenAI's Codex AI, which powers GitHub Copilot, was used to generate exploit scripts to confirm the vulnerability.
- Amazon, Cloudflare, Google, and Microsoft have issued patches or mitigations to address the flaw.
- The attack abuses the protocol's ability to cancel requests, creating a resource-intensive loop.
- Streaming providers using HTTP/2 are advised to update infrastructure immediately to prevent exploitation.
Why It Matters
This HTTP/2 vulnerability presents an immediate operational risk for streaming services, as unpatched servers are susceptible to rapid shutdown. Given the widespread use of HTTP/2 for content delivery, the incident underscores the need for continuous vigilance in protocol-level security and prompt patching cycles across the media supply chain. Monitoring the speed and completeness of patch deployments across the vendor ecosystem will indicate overall industry resilience.
Additional Context
The newly disclosed 'HTTP/2 Bomb' exploit, also tracked as CVE-2026-49975, affects major web servers including nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, leveraging their default HTTP/2 configurations (SecurityWeek, June 2026). Calif security researchers, who discovered the vulnerability using OpenAI’s Codex, noted that the attack can be launched from a home computer with a 100 Mbps connection and can render targeted servers unavailable within seconds (SecurityWeek, June 2026). The exploit combines a compression bomb, targeting HTTP/2’s HPACK header compression, with a Slowloris-style hold that prevents the server from freeing memory (CSO Online, June 2026). While some components of this attack have been known for a decade, Codex's ability to compose them into a functional exploit highlights AI's evolving role in security research—both for defense and offense (SecurityWeek, June 2026). Nginx released a fix in April (v1.29.8+), and Apache followed in late May (mod_http2 v2.0.41), while Microsoft IIS, Envoy, and Cloudflare Pingora had yet to release patches at the time of publication (CSO Online, June 2026). For unpatched systems, disabling HTTP/2 or fronting servers with solutions that cap header counts are recommended temporary mitigations (Cyber Security News, June 2026).
Read full article at techradar.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source