Plan
active
CDN Tsunami: HTTP/3-to-1.1 Translation Enables 350x DoS Amplification
- Engineer — Plan: If your origin sits behind a CDN that terminates HTTP/3, verify your CDN vendor has addressed this class of amplification and ensure your origin enforces its own rate limits independent of CDN-layer protections — CDN Tsunami demonstrates that relying solely on CDN-side controls can leave the origin exposed to amplified floods.
- SOC/IR — Learn: No active exploitation or IOCs reported; the attack surface is origin-server availability rather than a detectable intrusion behavior, so there is no detection rule or hunt to build today — file as background on CDN-based availability risk.
- Leader — Learn: Novel research with no reported exploitation means no immediate risk-register update is warranted, but CISOs who depend on CDN availability SLAs for customer-facing services should note this as context for future CDN vendor security reviews.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.