Hacker News new | ask | show | jobs
by slivanes 1777 days ago
I'm not seeing anything about this in nginx changelogs (or matching CVE's) either. Disabling http2 for now.
1 comments

Why would an Apache bug show up in Nginx changelogs?
It would not, but given how widespread this issue is it seems likely nginx is vulnerable, and sensible to assume it is unless otherwise demonstrated.

It’s not like the feature is super useful in general.