This vulnerability no longer exists, but it’s a good description of a non-obvious bug.
Via a post on mnot’s blog discussing HTTP/2.0 header compression.
Via a post on mnot’s blog discussing HTTP/2.0 header compression.