HTTP 1.1 connection reuse is indeed more subtle than it first appears. But http/2 is so hard to get right.
HTTP 1.1 connection reuse is indeed more subtle than it first appears. But http/2 is so hard to get right.
The underlying vulnerability, tracked as CVE-2025-8671, has been found to impact projects and organizations such as AMPHP, Apache Tomcat, the Eclipse Foundation, F5, Fastly, gRPC, Mozilla, Netty, Suse Linux, Varnish Software, Wind River, and Zephyr Project. Firefox is not affected.
[1] - https://www.securityweek.com/madeyoureset-http2-vulnerabilit...
Perhaps something like "HTTP/2-Lite" profile is in order? A minimal profile with just 1 connection, no compression, and so on.
I would endorse your idea, though, speaking more broadly! That does sound useful.
Perhaps it isn’t that easy, but it could be put in common and used a bit everywhere.