OpenAI’s Codex helps uncover the HTTP/2 Bomb DoS attack that can destroy more than 30 GB of RAM in seconds, knocking web servers offline before they can respond.


  • New DoS technique called HTTP/2 Bomb
  • Exploits blocking compression and flow control
  • Top Web Servers Confirmed Vulnerable

We can thank AI for a new denial of service (DoS) technique that can take a server offline in just seconds, using nothing more than a single computer with a 100 Mbps connection.

Earlier this week, cybersecurity researchers in California revealed that they had discovered a new DoS technique called HTTP/2 Bomb. They used OpenAI’s Codex software agent to find out, saying it combines two previously known HTTP/2 DoS methods: HPACK compression amplification and Slowloris-style resource retention via HTTP/2 flow control blocking.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top