CuraSec

Plan active

CDN Tsunami: HTTP/3-to-1.1 Translation Enables 350x DoS Amplification

2026-08-22 11:32 UTC · The Hacker News · read the source ↗ #cdn#dos-amplification#http3
  • Engineer — Plan: If your origin sits behind a CDN that terminates HTTP/3, verify your CDN vendor has addressed this class of amplification and ensure your origin enforces its own rate limits independent of CDN-layer protections — CDN Tsunami demonstrates that relying solely on CDN-side controls can leave the origin exposed to amplified floods.
  • SOC/IR — Learn: No active exploitation or IOCs reported; the attack surface is origin-server availability rather than a detectable intrusion behavior, so there is no detection rule or hunt to build today — file as background on CDN-based availability risk.
  • Leader — Learn: Novel research with no reported exploitation means no immediate risk-register update is warranted, but CISOs who depend on CDN availability SLAs for customer-facing services should note this as context for future CDN vendor security reviews.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.