CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Aug 20, 2026

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server.

The attacks, collectively named “CDN Tsunami,” were evaluated against Alibaba, Baidu,

Get Free Report & Network Analysis

Please check your email for the free report.