• News/
  • https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/

New 'HTTP/2 Rapid Reset' zero-day attack breaks DDoS records

BleepingComputer
·
Published Oct 10, 2023
·
Updated

A new DDoS (distributed denial of service) technique named 'HTTP/2 Rapid Reset' has been actively exploited as a zero-day since August, breaking all previous records in magnitude. News of the zero-day technique comes as a coordinated announcement today between Amazon Web Services, Cloudflare, and Google, who report mitigating attacks reaching 155 million requests per second (Amazon), 201 million rps (Cloudflare), and a record-breaking 398 million rps (Google). Google says they were able to mitigate these new attacks by adding further capacity on the edge of their network. Cloudflare comments that the size of the attack it mitigated is three times bigger than its previous record, from February 2023 (71 million rps), and it's alarming that this was achieved using a relatively small botnet comprising 20,000 machines. Since late August, Cloudflare has detected and mitigated over a thousand 'HTTP/2 Rapid Reset' DDoS attacks that surpassed 10 million rps, with 184 breaking the previous 71 million rps record. Cloudflare is confident that as further threat actors employ more expansive botnets along with this new attack method, HTTP/2 Rapid Reset attacks will continue to break even greater records. "There are botnets today that are made up of hundreds of thousands or millions of machines," comments Cloudflare. "Given that the entire web typically sees only between 1–3 billion requests per second, it's not inconceivable that using this method could focus an entire web's worth of reque...

Read full article

Affected Software

2 affected components
IETF HTTP/2
Various HTTP/2 proxy/load-balancer implementations
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new DDoS attack technique called 'HTTP/2 Rapid Reset' that exploits a zero-day vulnerability.

2

What security implications are discussed?

The article highlights the severe risk posed by the 'HTTP/2 Rapid Reset' attack, which breaks previous DDoS attack records in magnitude.

3

What products or software are affected?

The attack affects systems utilizing the HTTP/2 protocol, although specific affected software is not identified.

4

When was this zero-day attack first exploited?

The 'HTTP/2 Rapid Reset' zero-day attack has been actively exploited since August.

5

How does the 'HTTP/2 Rapid Reset' technique work?

The article provides an overview of the technique but does not go into specific technical details.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203