---
title: "Understanding the Recent DDoS Attack Against Read the Docs"
slug: understanding-the-recent-ddos-attack-against-read-the-docs
url: https://listedarticles.com/articles/understanding-the-recent-ddos-attack-against-read-the-docs
canonical_url: https://about.readthedocs.com/blog/2026/09/2026-ddos-attack/
content_type: blog_post
language: en
published_at: 2026-09-08T00:00:00.000Z
updated_at: 2026-09-16T16:11:22.119Z
author: "David Fischer"
authored_by: agent
publisher: "Read the Docs"
publisher_url: https://about.readthedocs.com
topics: ["DDoS", "Security", "Infrastructure", "Cloudflare", "DevOps", "Web Operations"]
license: all-rights-reserved
word_count: 269
reading_minutes: 1
citation: "David Fischer, Read the Docs. \"Understanding the Recent DDoS Attack Against Read the Docs.\" 8 Sept 2026. https://about.readthedocs.com/blog/2026/09/2026-ddos-attack/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# Understanding the Recent DDoS Attack Against Read the Docs

> Read the Docs describes a ten-day DDoS attack in June 2026 that peaked at 5.5 million requests per minute, roughly 100 times normal traffic. The attackers deliberately targeted cache-miss URLs, randomised TLS and HTTP headers to evade signature-based filters, and adapted their tactics within minutes of each defensive measure the team deployed.

> **Indexed summary.** This entry is an agent-written synopsis of an article first published at [about.readthedocs.com](https://about.readthedocs.com/blog/2026/09/2026-ddos-attack/). Read the original for the full text.

The attack was the largest and most sophisticated DDoS in Read the Docs' history, combining global IP distribution across millions of addresses with deliberate cache evasion. Unlike earlier incidents where IP-based rate limiting sufficed, this attack required layered, edge-first defences and real-time rule iteration through Cloudflare and Terraform-managed WAF rules.

## Key points

- At peak, traffic hit 5.5 million requests per minute against a normal baseline under 100k; the attack lasted nearly ten days.
- Attackers randomised HTTP headers and TLS parameters to defeat JA3/JA4 signature filters, and specifically targeted 302 redirects and 404 pages that bypassed the CDN cache.
- When the team moved 302 redirects to be served at the edge by Cloudflare, the attackers simply shifted to different hosts and endpoints within 30 minutes.
- Key defensive measures: rate limiting combining bot probability scores with per-IP limits; a "penalty box" for fingerprints generating too many expensive (non-200) responses; aggressive caching of redirects and error pages.
- IP-based blocking is now effectively useless against distributed botnets routing through residential proxies and large ASNs.
- All edge and WAF rules are managed through Terraform, which allowed the team to review, version-control, and deploy complex filtering rules quickly under pressure.

## Why it matters

Read the Docs hosts documentation for thousands of open-source projects, so its availability directly affects developer productivity across the ecosystem. The detailed post-mortem is valuable for any team running high-traffic infrastructure that must remain available during sustained, adaptive attacks.

---

*Source: [Understanding the Recent DDoS Attack Against Read the Docs](https://about.readthedocs.com/blog/2026/09/2026-ddos-attack/)*
