CVE-2023-44487 KEV EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-10-31.
Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-400 |
| On CISA KEV | yes — remediate by 2023-10-31 |
| Public exploit | yes |
| Published | 2023-10-10 |
| Last modified | 2026-08-11 |
CISA KEV
| Name | HTTP/2 Rapid Reset Attack Vulnerability |
|---|---|
| Added | 2023-10-10 |
| Due | 2023-10-31 |
| Vendor / product | IETF / HTTP/2 |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| caddyserver | caddy |
| eclipse | jetty |
| envoyproxy | envoy |
| f5 | big-ip access policy manager |
| f5 | big-ip advanced firewall manager |
| f5 | big-ip advanced web application firewall |
| f5 | big-ip analytics |
| f5 | big-ip application acceleration manager |
| f5 | big-ip application security manager |
| f5 | big-ip application visibility and reporting |
| f5 | big-ip carrier-grade nat |
| f5 | big-ip ddos hybrid defender |
| f5 | big-ip domain name system |
| f5 | big-ip fraud protection service |
| f5 | big-ip global traffic manager |
| f5 | big-ip link controller |
| f5 | big-ip local traffic manager |
| f5 | big-ip next |
| f5 | big-ip next service proxy for kubernetes |
| f5 | big-ip policy enforcement manager |
| f5 | big-ip ssl orchestrator |
| f5 | big-ip webaccelerator |
| f5 | big-ip websafe |
| golang | go |
| golang | http2 |
| golang | networking |
| ietf | http |
| netty | netty |
| nghttp2 | nghttp2 |
| siemens | ruggedcom ape1808 |
| siemens | ruggedcom ape1808 firmware |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware |
| siemens | simatic s7-1500 cpu 1518f-4 pn\/dp mfp |
| siemens | simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware |
| siemens | sinec ins |
| siemens | sinec nms |
| siemens | siplus s7-1500 cpu 1518-4 pn\/dp mfp |
| siemens | siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware |
| siemens | st7 scadaconnect |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HTTP/2 2.0 - Denial Of Service (DOS) | 2025-09-16 |
References
- http://www.openwall.com/lists/oss-security/2023/10/10/6
- http://www.openwall.com/lists/oss-security/2023/10/10/7
- http://www.openwall.com/lists/oss-security/2023/10/13/4
- http://www.openwall.com/lists/oss-security/2023/10/13/9
- http://www.openwall.com/lists/oss-security/2023/10/18/4
- http://www.openwall.com/lists/oss-security/2023/10/18/8
- http://www.openwall.com/lists/oss-security/2023/10/19/6
- http://www.openwall.com/lists/oss-security/2023/10/20/8
- https://access.redhat.com/security/cve/cve-2023-44487
- https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
- https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
- https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
- https://blog.vespa.ai/cve-2023-44487/
- https://bugzilla.proxmox.com/show_bug.cgi?id=4988
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803
- https://bugzilla.suse.com/show_bug.cgi?id=1216123
- https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
→ the Explorer · watch your stack · NVD