Research · Tag · Http2

Posts tagged http2.

4 entries · sorted: recency← All research
KASPA
2026-08-10

rusty-kaspa gRPC pre-auth HTTP/2 stream flood causing inbound-peering exhaustion and eviction

A pre-auth HTTP/2 stream flood on the rusty-kaspa gRPC P2P endpoint causes inbound-peering exhaustion via eviction and admission denial.

Simon Morley
Read →3 min read
WALRUS
2026-08-10

Walrus storage-node HTTP/2 Rapid Reset: memory exhaustion via u32::MAX default

Walrus storage-node's HTTP/2 server ships with `http2_max_pending_accept_reset_streams = u32::MAX`, disabling the post-CVE-2023-44487 accounting limit. An unauthenticated attacker forces rapid stream resets, accumulating unbounded pending-accept-reset state → memory pin → OOM with no GOAWAY to shed load.

Simon Morley
Read →6 min read
RESEARCH
2026-07-22

One prior-knowledge h2c connection multiplexes N eth_getLogs past an L4 per-connection cap on go-ethereum's JSON-RPC port

go-ethereum's JSON-RPC port terminates cleartext HTTP/2 (h2c) by prior knowledge, so one TCP connection can multiplex N eth_getLogs streams past an L4 edge that only caps connections per IP (nginx stream limit_conn) — measured 20/20 streams and ~39 MB pulled through a single connection the edge counts as one, an amplification-multiplexing bypass of a connection cap, not of an L7 request rate limit.

Simon Morley
Read →7 min read
RESEARCH
2026-07-22

Bypassing go-ethereum's --http.vhosts host allowlist with an empty Host, forged by an HAProxy HTTP/2→1.1 downgrade

An HTTP/2 request with an empty :authority, downgraded to HTTP/1.1 by an HAProxy front, reaches go-ethereum with an empty Host header that its --http.vhosts allowlist accepts (200) though it rejects any concrete disallowed host (403) — a bypass of geth's anti-DNS-rebinding Host filter by an attacker with raw-HTTP/2 reach to the edge.

Simon Morley
Read →7 min read