HTTP/2 Rapid Reset: deconstructing the record-breaking attack
blog.cloudflare.com
blog.cloudflare.com
But at this scale, I doubt someone is trying to do this just for the fun of it.
https://www.cve.org/CVERecord?id=CVE-2023-44487
(and yes, that includes this article here as well).
https://github.com/nginx/nginx/commit/6ceef192e7af1c507826ac...
Edit: seems it is a mirror from http://hg.nginx.org/nginx/
Conjecture on my part but their example of a photo album loading 100 images at once might come up where the page html/js/css are served up from one domain and the resulting page immediately tried to load images from a separate content server which has the lower limit. Maybe try updating your test to use two servers, one that serves up a page with 100 img tags, all different img resources being loaded from the second server, and the second server has the low concurrency limit. That might result in the browser issuing 100 immediate requests to server 2 without awaiting the SETTINGS frame.
When you use cloudflare, or any other CDN, you either give them a certificate for your domain, or use DNS to allow them to acquire a certificate on your behalf.