All news
HTTP/2
(2 articles)June 3, 2026
HTTP/2 Bomb Vulnerability: DoS Risk on NGINX & Apache
A new HTTP/2 bomb vulnerability lets attackers remotely crash NGINX, Apache, IIS, Envoy, and Cloudflare. Here's what developers need to know and do now.

May 5, 2026
Apache HTTP/2 CVE-2026-23918: DoS and RCE Risk
CVE-2026-23918 in Apache HTTP/2 enables denial of service and potential remote code execution. Learn what's exposed and how to patch now.