5 Comments
User's avatar
glendc's avatar

Checked if https://ramaproxy.org/ is vulnarable to it, but no, seems we are fine :) On all parts of it. Thank you for the published research btw!

Louis Tsang's avatar

Does CDN service provider like Cloudflare / AKAMAI stop the HTTP/2 bomb as they are terminated at edge point?

Yan Avlasov's avatar

OP ignored responsible disclosure policy and released a 0-day for Envoy ecosystem. Envoy community was in process of releasing a patch for this problem: https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8

Calif's avatar

Thanks for fixing the issue so quickly — this is a win for Envoy users. We believe the traditional disclosure model is increasingly outdated in the era of AI-assisted vulnerability discovery, and we explain our rationale for disclosure in the post.

phlax's avatar

responsible disclosure?