From my reading this is a problem if:
1. Your CDN/Load balancer allows for HTTP/1.1 connections
2. You do some filtering/firewalling/auth/etc at your CDN/Load balancer for specific endpoints
I'm sure it's more than that, and I'm just missing it.
If you do all your filtering/auth/etc on your backend servers this doesn't matter right? Obviously people DO filtering/auth/etc at the edge so they would be affected but 1/3rd seems high. Maybe 1/3rd of traffic is HTTP/1.1 but they would also have to be doing filtering/auth at the edge to be hit by this right?
Again, for the 3rd time, I'm probably missing something, just trying to better understand the issue.