HTTP/2 Bomb exploits HPACK and flow control; a single client can hold 32GB memory in 20 seconds, causing server outages.
Researchers who found the bug warn that its Moderate rating understates a threat reaching across LLM gateways, MCP servers ...