{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/praxis/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Praxis (\u003c 0.5.2)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","http2","proxy","memory-exhaustion"],"_cs_type":"advisory","_cs_vendors":["Praxis"],"content_html":"\u003cp\u003ePraxis, a proxy server built on the Pingora framework, is vulnerable to an HTTP/2 HPACK bomb attack. This vulnerability stems from a failure to correctly configure H2Options within the proxy's session initialization logic. Specifically, the affected version (v0.5.1 and earlier) does not enforce limits on the maximum header list size or the number of concurrent HTTP/2 streams. An attacker can exploit this by sending specially crafted, highly compressed HTTP/2 headers that cause the server to perform excessive memory allocations upon decompression. Observed testing indicates that a small volume of requests can force memory usage to spike from approximately 6MB to over 700MB, resulting in persistent memory exhaustion and potential service disruption. This vulnerability was fixed by implementing explicit H2Options in the handler configuration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify a target infrastructure utilizing a vulnerable version of the Praxis proxy.\u003c/li\u003e\n\u003cli\u003eAttacker establishes an HTTP/2 connection with the target server.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a series of malicious HTTP/2 requests containing high-compression ratio HPACK headers.\u003c/li\u003e\n\u003cli\u003eThe target server's HPACK decoder receives the headers and attempts to decompress the payload.\u003c/li\u003e\n\u003cli\u003eDue to the lack of header list size or stream limits, the server allocates significant memory buffers to process the input.\u003c/li\u003e\n\u003cli\u003eAttacker repeats the request cycle to maximize memory pressure on the host environment.\u003c/li\u003e\n\u003cli\u003eThe server encounters resource exhaustion, leading to degraded performance or service crashes.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service state for the Praxis proxy instance. Attackers can trigger rapid memory growth, causing potential process termination or impacting the availability of other co-located services on the same infrastructure. The vulnerability affects users of Praxis version 0.5.1 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of the Praxis proxy to version 0.5.2 or later to incorporate the corrected H2Options configuration.\u003c/li\u003e\n\u003cli\u003eImplement rate limiting and connection concurrency limits at the infrastructure layer (e.g., Load Balancer or WAF) to mitigate potential HTTP/2 flood and resource exhaustion attacks.\u003c/li\u003e\n\u003cli\u003eMonitor memory utilization metrics for proxy container instances; establish alerts for anomalous spikes in memory consumption associated with HTTP/2 traffic patterns.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T04:50:44Z","date_published":"2026-10-03T04:50:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-praxis-h2-bomb/","summary":"The Praxis proxy server is susceptible to a denial-of-service attack due to improper HTTP/2 header processing, allowing unauthenticated attackers to exhaust server memory through crafted HPACK compression sequences.","title":"Praxis Proxy HTTP/2 HPACK Bomb Denial-of-Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-praxis-h2-bomb/"}],"language":"en","title":"CraftedSignal Threat Feed - Praxis","version":"https://jsonfeed.org/version/1.1"}