Hacker News new | ask | show | jobs
by cpburns2009 45 days ago
> When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream.

Emphasis is mine. How much heavy lifting is this phrase doing?

1 comments

Definitely interested in this as well.