Description
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Problem types
CWE-770 Allocation of Resources Without Limits or Throttling
Product status
17.5.0 before *
17.1.0 before *
16.1.0 before *
15.1.0 before *
20.3.0 before *
2.0.0 before *
1.7.0 before *
2.0.0 before *
1.1.0 before *
2.0.0 before *
Credits
F5 acknowledges Gal Bar Nahum, Anat Bremler-Barr and Yaniv Harel for bringing this issue to our attention and following the highest standards of coordinated disclosure.
References
my.f5.com/manage/s/article/K000152001