It looks like all servers (except LiteSpeed) are affected by a new zero-day vulnerability called HTTP/2 Rapid Reset attack. Google, Cloudflare, and AWS disclosed the new zero-day vulnerability:

Because the attack abuses an underlying weakness in the HTTP/2 protocol, we believe any vendor that has implemented HTTP/2 will be subject to the attack.

– Cloudflare


LiteSpeed is flexing their muscle, saying it is immune to the zero-day vulnerability: