HackerFeeds

CyberSecurity News

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

The Hacker News
· August 20, 2026

AI summary

Cybersecurity researchers have identified two denial-of-service attacks that take advantage of how content delivery networks convert HTTP/3 traffic to HTTP/1.1 requests. This conversion process can amplify a low-bandwidth request stream by up to 350 times, targeting the origin server. The attacks, known as CDN Tsunami, were tested against several major content delivery networks, including those of Alibaba and Baidu. The amplification occurs when client-facing HTTP/3 traffic is translated into HTTP/1.1 requests, allowing a small amount of traffic to be magnified into a much larger amount. This can potentially overwhelm the origin server, leading to a denial-of-service condition. The CDN Tsunami attacks highlight a vulnerability in the way content delivery networks handle HTTP/3 traffic conv

Read the full article at The Hacker Newsthehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.