oss-sec: HTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora
Disclosure We disclosed the issue to nginx in April. They responded by importing the max_headers directive from freenginx, shipping it in 1.29.8 the next day: h...
America Forever Bytes
Technology
Disclosure We disclosed the issue to nginx in April. They responded by importing the max_headers directive from freenginx, shipping it in 1.29.8 the next day: h...
xeloxa has realised a new security note Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service