Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

HTTP/2: The Sequel is Always Worse

Summary

HTTP/2-exclusive desync attacks: implementation flaws and RFC imperfections enable cache poisoning, credential theft and request tunnelling against ALB, WAFs and CDNs, netting multiple max bounties.
Published
Collected

original ↗

Related coverage

back