HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Source: NVD ↗ · CISA KEV Catalog ↗