Description
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
Remediation
References
Related Vulnerabilities
WordPress Plugin Awesome Studio Cross-Site Scripting (1.0.7)
MySQL CVE-2021-2481 Vulnerability (CVE-2021-2481)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-28735)
Oracle JRE CVE-2014-2398 Vulnerability (CVE-2014-2398)
e107 Inadequate Encryption Strength Vulnerability (CVE-2021-27885)