Skip to content

Comment on HTTP/1.1 must die: the desync endgameparent

Comments

Speaking of http/2 [1] - August 14, 2025

The underlying vulnerability, tracked as CVE-2025-8671, has been found to impact projects and organizations such as AMPHP, Apache Tomcat, the Eclipse Foundation, F5, Fastly, gRPC, Mozilla, Netty, Suse Linux, Varnish Software, Wind River, and Zephyr Project. Firefox is not affected.

[1] - https://www.securityweek.com/madeyoureset-http2-vulnerabilit...

Protocol smuggling is a lot more severe than DoS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.