The 'CDN Tsunami' Attack Turns a Trickle of Traffic Into a Flood at the Origin
Researchers show how the way big content delivery networks translate modern HTTP/3 requests into older HTTP/1.1 can multiply a small attack stream by up to 350 times against the website behind them.

Key points
- Researchers disclosed two denial-of-service attacks, collectively called CDN Tsunami, that abuse how large content delivery networks convert HTTP/3 traffic into HTTP/1.1 requests to the origin website.
- A low-bandwidth request stream can be amplified by up to 350 times against the origin server sitting behind the CDN.
- Alibaba and Baidu, two of the largest CDN operators in China, were both tested.
- The problem sits in the translation layer between protocol versions, not in HTTP/3 itself.
- Websites hidden behind affected CDNs could be knocked offline by a single attacker with modest resources.
Security researchers have published details of a pair of denial-of-service attacks that turn the big infrastructure companies protecting websites into unwitting amplifiers. The technique is called CDN Tsunami, first reported by The Hacker News.
A content delivery network, or CDN, is a company that sits in front of a website and forwards genuine requests to the actual server. When a CDN receives requests in the newest web protocol, HTTP/3, and rewrites them into the older HTTP/1.1 format that many origin servers still expect, an attacker can craft the incoming traffic so the outgoing version is vastly larger. A small trickle in, a torrent out, up to 350 times larger according to the write-up.
What is actually being exploited?
The translation step between protocols is the weak point, not HTTP/3 itself. HTTP/3 is the newest version of the web's core protocol, designed to be faster on flaky connections. Origin servers, the machines that actually host a site's content, often still speak the older HTTP/1.1, so the CDN acts as an interpreter.
Both attacks abuse features of HTTP/3, including compact headers and request multiplexing, that balloon in size once the CDN rewrites them for the older protocol. It's an amplification trick, and it's one of the oldest in the denial-of-service playbook, going back to DNS reflection in the 2000s. What's new is the amplifier: a paid, industrial-scale CDN doing exactly what it was configured to do. Alibaba's CDN infrastructure has come up here before: our 10 July story covered a separate flaw in its XQUIC stack that could crash an HTTP/3 server with just 260 bytes.
Who was tested, and were they vulnerable?
The researchers evaluated the attacks against Alibaba and Baidu, two of the largest CDN operators in China. Both handle a substantial share of Asian web traffic, so a workable attack against their translation logic isn't academic. The disclosure reads like a measured result, not a hypothetical.
| Detail | Value |
|---|---|
| Attack name | CDN Tsunami |
| Attacks disclosed | 2 |
| Peak amplification | Up to 350x |
| CDNs tested | Alibaba, Baidu |
| Protocol abused | HTTP/3 to HTTP/1.1 translation |
Should ordinary internet users worry?
Not directly. There's no data breach here and no personal information is at risk from the technique itself. The people who need to pay attention are operators of websites sitting behind a CDN, especially anyone whose origin server is sized on the assumption that the CDN will smooth traffic rather than concentrate it.
If your favourite booking site or bank goes dark for an afternoon, this class of attack is one plausible reason. Nothing to do at your end beyond the usual: try again later, and be wary of any "the site is down, click here to log in" messages that arrive by email while an outage is in the news.
What should CDN customers do now?
Ask your provider whether their HTTP/3 front end and their HTTP/1.1 origin path have been reviewed for this specific amplification pattern. Rate limits at the origin help, as does capping the size and count of translated headers. Neither fix is exotic engineering. The responsibility belongs to the CDN, not the customer, but a polite email focuses minds.



