Tag
This article describes using fuzzing to discover an unauthenticated denial-of-service vulnerability in snac2's JSON parser, allowing remote crashes via crafted inputs.
GNU Guix discloses multiple security vulnerabilities in 'guix substitute' and 'guix pull' that allow remote privilege escalation to the build daemon user, remote store corruption, potential local file disclosure, and denial-of-service; users are urged to upgrade immediately.
Researchers used OpenAI's Codex agent to chain two decade-old DoS techniques into an HTTP/2 Bomb that can crash vulnerable web servers in seconds, affecting major servers like nginx, Apache, IIS, Envoy, and Pingora.
Codex discovered a remote denial-of-service exploit dubbed 'HTTP/2 Bomb' that targets HPACK compression in major web servers (nginx, Apache, IIS, Envoy, Pingora), chaining a compression bomb with flow-control hold to exhaust server memory quickly.
A Python DDoS script with 57 attack methods shared on GitHub.