OpenAI’s Codex helps uncover the HTTP/2 Bomb DoS attack that can destroy more than 30 GB of RAM in seconds, taking web servers offline before they can react.



  • New DoS technique called HTTP/2 bomb
  • Take advantage of compression stagnation and flow control
  • Major web servers confirmed to be vulnerable

We can thank AI for a new denial of service (DoS) technique that can take a server offline in a matter of seconds, using nothing more than a single computer with a 100 Mbps connection.

Earlier this week, California cybersecurity researchers revealed they had discovered a new DoS technique called HTTP/2 Bomb. They used OpenAI’s Codex software agent to discover it, saying it combines two previously known HTTP/2 DoS methods: HPACK compression amplification and Slowloris-style resource retention using HTTP/2 flow control.

Leave a Comment

Your email address will not be published. Required fields are marked *