[rwth-security] New Attack Bypasses HTTP/2 Security for Arbitrary Cross-Site Scripting