Collected research
HTTP/2 CONTINUATION Flood: Technical Details
HTTP/2 `CONTINUATION` Flood: Technical Details
HTTP/2 splits oversized header blocks across CONTINUATION frames terminated by the END_HEADERS flag. Withholding that flag leaves many implementations parsing and storing headers indefinitely: the article documents CPU exhaustion, out-of-memory crashes from one or many connections, and crashes after a handful of frames in servers including Apache httpd, Envoy and Go's HTTP/2 stack. The requests never complete, so they leave no trace in access logs.
Record
- Document
- HTTP/2 `CONTINUATION` Flood: Technical Details
- Researcher
- Bartek Nowotarski
- Published by
- nowotarski.info
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Bartek Nowotarski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .