HTTP/2 Crash: A Denial of Service (DoS) in HTTP/2 Flow Control
Okta, Monday, August 3rd, 2026
The Okta Red Team discloses a denial-of-service vulnerability in HTTP/2 flow control.
The Okta Red Team has disclosed a denial-of-service vulnerability in HTTP/2 flow control.
The writeup details how the flow control mechanism can be abused to crash or exhaust affected server implementations.
Because flow control is a core protocol feature, the issue potentially affects multiple independent implementations.
Okta published the research on its security blog alongside remediation guidance.