HTTP/2 vulnerability: CONTINUATION Flood


Is there any announcement from AWS for the new http/2 vulnerability discovered and if/how affects AWS http/2 related services?

Vulnerability discovery announcement:

Sorry in advance if there is something posted which I haven't found!

1 Respuesta
Respuesta aceptada

AWS is aware of a recent publication from CERT/CC [1] related to HTTP/2 CONTINUATION frames, which can be used in a denial of service (DoS) attack. CloudFront, Application Load Balancer, and API Gateway are not affected by this issue.

Customers running their own web servers should use AWS Shield Advanced [2] and engage the Shield Response Team [3] to deploy mitigations in the event of a DoS attack.

Security-related questions or concerns can be brought to our attention via




profile pictureAWS
respondido hace 2 meses
profile picture
revisado hace 2 meses
  • Thanks for your answer! My main concern was about CloudFront, Application Load Balancer, and API Gateway :)

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas