CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

August 20, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Websites hosted on major CDN providers
Incident: Discovery of a DoS amplification vulnerability dubbed ‘CDN Tsunami’ affecting six major CDN providers.
Impact: Potential for severe origin server resource exhaustion and denial of service via bandwidth amplification.
Attacker: Unidentified threat actors
Analysis: The ‘CDN Tsunami’ attack exploits a protocol gap where CDNs use HTTP/3 at the edge but HTTP/1.1 for origin communication. By abusing QPACK header compression, attackers can send tiny requests that expand into massive headers at the origin server. This discrepancy creates a significant bandwidth amplification vector that can overwhelm back-end infrastructure.
Recommendations: Review HTTP/3 configurations and edge-to-origin settings with your CDN provider; Implement strict rate limiting and request size monitoring at the origin server; Transition to end-to-end HTTP/3 support where possible to eliminate translation gaps
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *