[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjqxWwESB2WoPJUWekBYxOvD0UK2M_5NZPdccbh7t2f4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"90c9d4de-74b4-44da-8747-4e20b853fe37","http3-to-http11-translation-flaw-enables-350x-dos-amplification-via-cdns","60524d70-d7ea-49af-969f-769992d53a09","HTTP\u002F3-to-HTTP\u002F1.1 Translation Flaw Enables 350x DoS Amplification via CDNs","The CDN Tsunami attack exploits a fundamental design weakness in how major CDNs translate HTTP\u002F3 requests into HTTP\u002F1.1 when forwarding traffic to origin servers, allowing attackers to amplify low-bandwidth requests up to 350 times. The root problem lies in misconfigured or unvalidated protocol translation logic that fails to account for header multiplication and request expansion between protocol versions. Because mitigations are applied at the CDN layer rather than the origin, servers without additional protection remain exposed even when CDN-level fixes are deployed. This matters because organizations often treat CDNs as a complete shield, creating a dangerous false sense of security for origin infrastructure. Relying solely on third-party mitigations without hardening origin servers is an architectural risk that attackers can exploit directly.","**Immediate actions:**\n- Confirm whether your CDN provider (especially Baidu, Tencent, or others using HTTP\u002F3 gateways) has deployed patches for the CDN Tsunami vulnerability.\n- Implement origin-side rate limiting and request throttling independent of CDN-level controls to reduce amplification impact.\n- Temporarily restrict direct origin server access to only known CDN IP ranges while vendor patches are assessed.\n\n**Long-term improvements:**\n- Audit CDN configuration to ensure HTTP\u002F3 translation settings enforce strict header size and request count limits at the edge.\n- Adopt a defense-in-depth architecture so origin servers have independent DDoS protections rather than relying solely on CDN mitigation.\n- Maintain an up-to-date inventory of all internet-facing services and their dependency on CDN protocol translation features.\n\n**Detection measures:**\n- Deploy anomaly-based traffic monitoring at the origin to detect sudden spikes in HTTP\u002F1.1 request volume inconsistent with expected CDN throughput.\n- Set alerting thresholds for request amplification ratios between edge and origin layers to identify exploitation attempts early.\n- Integrate CDN access logs with your SIEM to correlate protocol-level anomalies with origin server load metrics in near real-time.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SC-5: Denial-of-Service Protection","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 SI-2: Flaw Remediation","NIST CSF DE.AE-1: Baseline of network operations established","OWASP API Security Top 10: API4:2023 Unrestricted Resource Consumption","ITIL: Availability Management — resilience and redundancy planning","published","2026-08-20T14:22:48.830194+00:00","2026-08-20T14:22:48.761+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fcdn-tsunami-attack-abuses-http3.html","cdn-tsunami-attack-abuses-http-3-translation-for-up-to-350x-dos-amplification-6740d0","CDN Tsunami Attack Abuses HTTP\u002F3 Translation for Up to 350x DoS Amplification",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]