Amazon, Google, and Cloudflare say a DDoS attack hit 398M RPS in August 2023, ~8x larger than the prior record, due to a new flaw; Google mitigated the attack
Assigner: Mitre Published: 2023-10-10Updated: 2023-10-11 The HTTP/2 protocol allows … Bill Toulas / BleepingComputer : New ‘HTTP/2 Rapid Reset’ zero-day attack breaks DDoS records Lucas Pardue / The Cloudflare Blog : HTTP/2 Rapid Reset: deconstructing the record-breaking attack Google Cloud Blog : Google mitigated the largest DDoS attack to date, peaking above 398 million rps Deeba Ahmed / Hackread : Google, Cloudflare, and AWS Disclose Largest DDoS Attack in History Metacurity : Zero-Day Vulnerability in HTTP/2 Protocol Caused Unprecedented Surge in DDoS Attacks Wes Davis / The Verge : Cloudflare, Google, and Amazon explain what's behind the largest DDoS attacks ever Pierluigi Paganini / Security Affairs : New ‘HTTP/2 Rapid Reset’ technique behind record-breaking DDoS attacks Cloudflare : Cloudflare Helps Discover New Online Threat That Led to Largest Attack in Internet History Cedric Pernet / TechRepublic : New DDoS Attack is Record Breaking: HTTP/2 Rapid Reset Zero-Day Reported by Google, AWS & Cloudflare Aaron Drapkin / Tech.co : Microsoft and Google Halt “Largest” Cyberattack on Record Connor Jones / The Register : HTTP/2 ‘Rapid Reset’ zero-day exploited in biggest DDoS deluge seen yet Luke Jones / WinBuzzer : Cybersecurity Firms Tackle Massive ‘HTTP/2 Rapid Reset’ Zero-Day DDoS Attacks Eduard Kovacs / SecurityWeek : Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks Leigh Mc Gowran / Silicon Republic : Big Tech firms reveal record-breaking DDoS attacks Phil Muncaster / Infosecurity : Tech Giants Reveal Record-Breaking “Rapid Reset” DDoS Bug TechRadar : Google says it blocked the largest DDoS attack ever detected Mastodon: Tarah Wheeler / @Tarah@infosec.exchange : My TL;DR on the new CVE 2023-44487 vuln. — There doesn't appear to be an actually good breakdown out there yet of this HTTP/2 vuln based around session resets. Even though it looks like AWS and Cloudflare did their jobs and patched, their blogs seem to have been thoroughly lawyered into corpspeak instead of being useful. … BrianKrebs / @briankrebs@infosec.exchange : There's an important vulnerability being disclosed today that allows attackers to massively increase the size of DDoS attacks. — The flaw is being tracked as CVE-2023-44487, a.k.a. “HTTP/2 Rapid Reset Attack.” According to Damian Menscher at Google, the attack “works by sending a request and then immediately cancelling it (a feature of HTTP/2). … X: Damian Menscher / @menscher : New DDoS threat: the Rapid Reset attack works by sending a request and then immediately cancelling it (a feature of HTTP/2). This lets attackers skip waiting for responses, resulting in a more efficient attack. #CVE-2023-44487 https://cloud.google.com/... 1/3 John Hultquist🌻 / @johnhultquist : Beware claims that this highly secretive operation was coordinated with DDOS attacks. Ryan Naraine / @ryanaraine : 0days everywhere 👀 Cloudflare, Google and AWS on a new zero-day named ‘HTTP/2 Rapid Reset’ being exploited by malicious actors to launch “the largest distributed denial-of-service (DDoS) attacks in internet history” https://www.securityweek.com/ ... <- reporting by @EduardKovacs @cloudflare : We've helped discover a new zero-day vulnerability-dubbed HTTP/2 Rapid Reset-that generated a DDoS attack 3X the size we've ever seen before. On our blog, we're sharing a full technical deep dive on what you need to know. https://cfl.re/... @eastdakota : This one is really bad. Make sure you have Layer 7 DDoS mitigation from @Cloudflare or someone else. Richard Seroter / @rseroter : I don't think anyone is expecting FEWER digital attacks on companies of any size. Last year, @googlecloud resisted a monster 46 million rps attack on a customer ( https://cloud.google.com/...). In Sept? We held back a 398 million rps attack. Here's how: https://cloud.google.com/... Lukasz Olejnik / @lukolejnik : DDoS attacks reached a peak of 398 million requests per second (rps), and relied on a novel HTTP/2 “Rapid Reset” technique based on stream multiplexing that has affected multiple Internet infrastructure companies https://cloud.google.com/... @nixcraft : Google mitigated the largest DDoS attack to date, peaking above 398 million rps: The attack used a novel technique, HTTP/2 Rapid Reset, based on stream multiplexing https://cloud.google.com/... Damian Menscher / @menscher : The only bottleneck is server processing speed, which makes this an extreme load-test for the victim. Our monitoring measured one attack, coming into our global network via a global network of open proxies, at 398M requests per second! https://cloud.google.com/... 2/3 LinkedIn: Kieran Broadfoot : Remarkable work from our Google engineers Tim April Juho Snellman Daniele Iamartino Damian Menscher. It's a genuine privilege to work with them every day. Jaspreet Singh Narang : Everyday I talk to customers about the security of their infrastructure whether it's onprem or on any cloud. … Carlos Henrique Silva Santana : Between late August and September 2023, Amazon Web Services detected and mitigated a new type of distributed denial of service (DDoS) … Grant Bourzikas : If you aren't aware of the recent vulnerability in the HTTP/2 protocol, you should read up. It was released today, and it will impact everyone on the Internet. … Gianluca Varisco : A number of Google services and Cloud customers have been targeted with a novel HTTP/2-based DDoS attack which peaked in August. … Gianluca Varisco : Over the last few years, Google's DDoS Response Team has observed the trend that distributed denial-of-service (DDoS) attacks are increasing exponentially in size. … Taylor Lehmann : Pure “7x largest DDoS mitigated” gold from Emil K. and a team of Googlers. — “This new series of DDoS attacks reached a peak of 398 million requests per second … Forums: Hacker News : The largest DDoS attack to date, peaking above 398M rps
Context & Ripple Effects
This is the latest escalation in a sequence of application-layer DDoS records: Google had previously blocked a 46M requests-per-second attack, while Cloudflare later reported dozens of attacks exceeding 71M RPS. The jump matters because the reported amplification came from a flaw in HTTP/2, a shared web protocol, rather than simply a larger traffic source.
Amazon, Google, and Cloudflare are therefore not just reporting another customer-targeted event; they are jointly surfacing a protocol-level exposure that affects the defensive assumptions of large internet-facing services.
First-order effects
- HTTP/2 operators and the cloud providers must deploy mitigations for Rapid Reset behavior, while Google’s successful mitigation shows that sufficiently scaled edge defenses can absorb the reported attack.
- Customers of AWS, Google, and Cloudflare gain immediate protection where providers apply those controls, but organizations operating their own HTTP/2 endpoints must assess whether their stacks are exposed.
Second-order effects
- DDoS-defense providers and application-delivery platforms face pressure to make request-rate controls and protocol-aware detection standard capabilities, rather than relying chiefly on bandwidth-based filtering.
- The event raises the value of using large distributed edge networks for exposed services, because a protocol flaw can generate request volumes beyond what a single organization can reasonably filter.
Third-order effects
- If shared-protocol flaws continue to drive record attacks, internet resilience will depend more heavily on coordinated disclosure, rapid software updates, and ecosystem-wide mitigation across cloud and network providers.
- The pattern could further concentrate DDoS resilience in the largest platforms: their scale helps protect customers, while also making provider-level security controls a more consequential dependency.
The trend: DDoS attacks are shifting from raw-traffic floods toward protocol-abuse campaigns that test the coordinated defenses of the internet’s largest platforms.