<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification]]></title><description><![CDATA[<p dir="auto">Researchers have identified two denial-of-service (DoS) attack techniques that abuse how large content delivery networks (CDNs) translate inbound HTTP/3 requests into HTTP/1.1 traffic destined for origin servers. Dubbed <strong>CDN Tsunami</strong>, these attack vectors achieve a low-bandwidth amplification factor of up to <strong>350x</strong> against the target backend.</p>
<p dir="auto">The attacks work by exploiting the protocol conversion process built into many CDN edge nodes. When a client speaks HTTP/3—typically over QUIC—the CDN unwraps that traffic and re-encodes it as HTTP/1.1 before forwarding it upstream. In specific implementations, this translation step can inflate a seemingly tiny request stream into a much heavier workload for the origin.</p>
<p dir="auto">The research team evaluated <strong>CDN Tsunami</strong> against several major providers, including Alibaba and Baidu. The core issue lies in how these edge nodes handle specific HTTP/3 features or frame sequences during the conversion to HTTP/1.1, allowing an attacker to send a sparse set of requests from a single connection and force the CDN into generating a massive burst of requests toward the website's server.</p>
<p dir="auto">Key details from the evaluation:</p>
<ul>
<li>Attack type: Denial-of-service via protocol translation (HTTP/3 to HTTP/1.1)</li>
<li>Amplification factor: Up to <strong>350x</strong> from a low-bandwidth source stream</li>
<li>Target surface: Origin servers behind participating CDN edge nodes</li>
<li>Tested providers: Alibaba, Baidu</li>
</ul>
<p dir="auto">No specific patch or CVE identifier has been attached to this research at the time of publication. The findings emphasize that the amplification potential depends on the CDN's internal request-generation logic rather than a single software bug. Mitigation strategies would likely involve tightening CDN rate controls, monitoring per-connection upstream request counts, and validating the request patterns your origin actually receives from edge nodes.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are any of your edge-to-origin configurations exposed to this kind of translation abuse, and have you checked your CDN's rate-limit thresholds for HTTP/3 to HTTP/1.1 conversion spikes?</p>
]]></description><link>https://xploitlk.com/topic/77/cdn-tsunami-attack-abuses-http-3-translation-for-up-to-350x-dos-amplification</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:26:45 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/77.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 24 Aug 2026 02:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>