HTTP/2 Bomb: Single-Attacker Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora
A newly disclosed exploit called the 'HTTP/2 Bomb' can exhaust tens of gigabytes of server memory in seconds using just a home internet connection. Five of the world's...
GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities
Security researchers have uncovered vulnerabilities in GitLab’s Community Edition and Enterprise Edition platforms, prompting the company to release critical security patches. On December 10th, 2025, Gitlab released update...
Analysis of recent high-severity vulnerabilities in GitLab and Atlassian products
Both GitLab and Atlassian have recently released critical security patches addressing a series of high-severity vulnerabilities across their core product lines. This coordinated disclosure and remediation effort underscores...
DoS vulnerability CVE-2024-56332 in Next.js, update now
Next.js, a popular React framework, has recently addressed a critical denial-of-service (DoS) vulnerability identified as CVE-2024-56332. This security flaw was discovered in the server actions feature of Next.js,...