Codex Discovered a Hidden HTTP/2 Bomb

Yenrabbit 26 points 3 comments June 02, 2026
blog.calif.io · View on Hacker News

Discussion Highlights (3 comments)

DiabloD3

After reading the article, I can conclude that Codex discovered nothing new. This is already something that is known, and if you're able to be targeted by this (which is not the majority of users) configure your httpd differently.

HDBaseT

Not ideal. This appears to be fixed as of April (at least for Apache). [0]. [0] - https://github.com/nginx/nginx/commit/365694160a85229a7cb006...

BobbyTables2

Couldn’t simple fuzzing have found this?

Semantic search powered by Rivestack pgvector
9,294 stories · 87,504 chunks indexed