CVE-2023-44487
HIGH CISA KEV EPSS 100.0%
Published Oct 10, 20232y ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
Published Oct 10, 2023 2y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Oct 10, 2023 2y ago
KEV Due Oct 31, 2023 973d overdue
Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
CISA Known Exploited Overdue 973d
- Added
- Oct 10, 2023
- Due
- Oct 31, 2023
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS Exploit Probability
100.0% percentile
Exploit & Patch Status
Actively Exploited (KEV)
Patch Available
Weaknesses 1
CWE-400 Uncontrolled Resource Consumption Resource Mgmt
Affected Products 464
| Vendor | Product | Version | Range |
|---|---|---|---|
| siemens | simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware | * | ≥3.1.5 |
| siemens | simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp | * | any |
| siemens | sinec_ins | * | <1.0 |
| siemens | sinec_ins | 1.0 | any |
| siemens | sinec_ins | 1.0 | any |
| siemens | sinec_ins | 1.0 | any |
| siemens | sinec_ins | 1.0 | any |
| siemens | sinec_ins | 1.0 | any |
| siemens | sinec_nms | * | <3.0 |
| siemens | st7_scadaconnect | * | <1.1 |
| siemens | ruggedcom_ape1808_firmware | * | any |
| siemens | ruggedcom_ape1808 | * | any |
| siemens | simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware | * | ≥3.1.5 |
| siemens | simatic_s7-1500_cpu_1518-4_pn\/dp | * | any |
| siemens | siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware | * | ≥3.1.5 |
| siemens | siplus_s7-1500_cpu_1518-4_pn\/dp_mfp | * | any |
| ietf | http | 2.0 | any |
| nghttp2 | nghttp2 | * | <1.57.0 |
| netty | netty | * | <4.1.100 |
| envoyproxy | envoy | 1.24.10 | any |
| envoyproxy | envoy | 1.25.9 | any |
| envoyproxy | envoy | 1.26.4 | any |
| envoyproxy | envoy | 1.27.0 | any |
| eclipse | jetty | * | <9.4.53 |
| eclipse | jetty | * | ≥10.0.0 – <10.0.17 |
| eclipse | jetty | * | ≥11.0.0 – <11.0.17 |
| eclipse | jetty | * | ≥12.0.0 – <12.0.2 |
| caddyserver | caddy | * | <2.7.5 |
| golang | go | * | <1.20.10 |
| golang | go | * | ≥1.21.0 – <1.21.3 |
| golang | http2 | * | <0.17.0 |
| golang | networking | * | <0.17.0 |
| f5 | big-ip_access_policy_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_access_policy_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_access_policy_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_access_policy_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_access_policy_manager | 17.1.0 | any |
| f5 | big-ip_advanced_firewall_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_advanced_firewall_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_advanced_firewall_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_advanced_firewall_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 | any |
| f5 | big-ip_advanced_web_application_firewall | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_advanced_web_application_firewall | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_advanced_web_application_firewall | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_advanced_web_application_firewall | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 | any |
| f5 | big-ip_analytics | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_analytics | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_analytics | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_analytics | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_analytics | 17.1.0 | any |
| f5 | big-ip_application_acceleration_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_application_acceleration_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_application_acceleration_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_application_acceleration_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_application_acceleration_manager | 17.1.0 | any |
| f5 | big-ip_application_security_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_application_security_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_application_security_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_application_security_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_application_security_manager | 17.1.0 | any |
| f5 | big-ip_application_visibility_and_reporting | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_application_visibility_and_reporting | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_application_visibility_and_reporting | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_application_visibility_and_reporting | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_application_visibility_and_reporting | 17.1.0 | any |
| f5 | big-ip_carrier-grade_nat | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_carrier-grade_nat | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_carrier-grade_nat | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_carrier-grade_nat | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_carrier-grade_nat | 17.1.0 | any |
| f5 | big-ip_ddos_hybrid_defender | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_ddos_hybrid_defender | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_ddos_hybrid_defender | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_ddos_hybrid_defender | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_ddos_hybrid_defender | 17.1.0 | any |
| f5 | big-ip_domain_name_system | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_domain_name_system | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_domain_name_system | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_domain_name_system | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_domain_name_system | 17.1.0 | any |
| f5 | big-ip_fraud_protection_service | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_fraud_protection_service | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_fraud_protection_service | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_fraud_protection_service | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_fraud_protection_service | 17.1.0 | any |
| f5 | big-ip_global_traffic_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_global_traffic_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_global_traffic_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_global_traffic_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_global_traffic_manager | 17.1.0 | any |
| f5 | big-ip_link_controller | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_link_controller | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_link_controller | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_link_controller | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_link_controller | 17.1.0 | any |
| f5 | big-ip_local_traffic_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_local_traffic_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_local_traffic_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_local_traffic_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_local_traffic_manager | 17.1.0 | any |
| f5 | big-ip_next | 20.0.1 | any |
| f5 | big-ip_next_service_proxy_for_kubernetes | * | ≥1.5.0 – ≤1.8.2 |
| f5 | big-ip_policy_enforcement_manager | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_policy_enforcement_manager | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_policy_enforcement_manager | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_policy_enforcement_manager | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_policy_enforcement_manager | 17.1.0 | any |
| f5 | big-ip_ssl_orchestrator | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_ssl_orchestrator | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_ssl_orchestrator | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_ssl_orchestrator | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_ssl_orchestrator | 17.1.0 | any |
| f5 | big-ip_webaccelerator | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_webaccelerator | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_webaccelerator | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_webaccelerator | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_webaccelerator | 17.1.0 | any |
| f5 | big-ip_websafe | * | ≥13.1.0 – ≤13.1.5 |
| f5 | big-ip_websafe | * | ≥14.1.0 – ≤14.1.5 |
| f5 | big-ip_websafe | * | ≥15.1.0 – ≤15.1.10 |
| f5 | big-ip_websafe | * | ≥16.1.0 – ≤16.1.4 |
| f5 | big-ip_websafe | 17.1.0 | any |
| f5 | nginx | * | ≥1.9.5 – ≤1.25.2 |
| f5 | nginx_ingress_controller | * | ≥2.0.0 – ≤2.4.2 |
| f5 | nginx_ingress_controller | * | ≥3.0.0 – ≤3.3.0 |
| f5 | nginx_plus | * | ≥r25 – <r29 |
| f5 | nginx_plus | r29 | any |
| f5 | nginx_plus | r30 | any |
| apache | tomcat | * | ≥8.5.0 – ≤8.5.93 |
| apache | tomcat | * | ≥9.0.0 – ≤9.0.80 |
| apache | tomcat | * | ≥10.1.0 – ≤10.1.13 |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apache | tomcat | 11.0.0 | any |
| apple | swiftnio_http\/2 | * | <1.28.0 |
| grpc | grpc | * | <1.56.3 |
| grpc | grpc | * | ≤1.59.2 |
| grpc | grpc | * | ≥1.58.0 – <1.58.3 |
| grpc | grpc | 1.57.0 | any |
| microsoft | .net | * | ≥6.0.0 – <6.0.23 |
| microsoft | .net | * | ≥7.0.0 – <7.0.12 |
| microsoft | asp.net_core | * | ≥6.0.0 – <6.0.23 |
| microsoft | asp.net_core | * | ≥7.0.0 – <7.0.12 |
| microsoft | azure_kubernetes_service | * | <2023-10-08 |
| microsoft | visual_studio_2022 | * | ≥17.0 – <17.2.20 |
| microsoft | visual_studio_2022 | * | ≥17.4 – <17.4.12 |
| microsoft | visual_studio_2022 | * | ≥17.6 – <17.6.8 |
| microsoft | visual_studio_2022 | * | ≥17.7 – <17.7.5 |
| microsoft | windows_10_1607 | * | <10.0.14393.6351 |
| microsoft | windows_10_1607 | * | <10.0.14393.6351 |
| microsoft | windows_10_1809 | * | <10.0.17763.4974 |
| microsoft | windows_10_21h2 | * | <10.0.19044.3570 |
| microsoft | windows_10_22h2 | * | <10.0.19045.3570 |
| microsoft | windows_11_21h2 | * | <10.0.22000.2538 |
| microsoft | windows_11_22h2 | * | <10.0.22621.2428 |
| microsoft | windows_server_2016 | * | any |
| microsoft | windows_server_2019 | * | any |
| microsoft | windows_server_2022 | * | any |
| nodejs | node.js | * | ≥18.0.0 – <18.18.2 |
| nodejs | node.js | * | ≥20.0.0 – <20.8.1 |
| microsoft | cbl-mariner | * | <2023-10-11 |
| dena | h2o | * | <2023-10-10 |
| proxygen | * | <2023.10.16.00 | |
| apache | apisix | * | <3.6.1 |
| apache | traffic_server | * | ≥8.0.0 – <8.1.9 |
| apache | traffic_server | * | ≥9.0.0 – <9.2.3 |
| amazon | opensearch_data_prepper | * | <2.5.0 |
| debian | debian_linux | 10.0 | any |
| debian | debian_linux | 11.0 | any |
| debian | debian_linux | 12.0 | any |
| kazu-yamamoto | http2 | * | <4.2.2 |
| istio | istio | * | <1.17.6 |
| istio | istio | * | ≥1.18.0 – <1.18.3 |
| istio | istio | * | ≥1.19.0 – <1.19.1 |
| varnish_cache_project | varnish_cache | * | <2023-10-10 |
| traefik | traefik | * | <2.10.5 |
| traefik | traefik | 3.0.0 | any |
| traefik | traefik | 3.0.0 | any |
| traefik | traefik | 3.0.0 | any |
| projectcontour | contour | * | <2023-10-11 |
| linkerd | linkerd | * | ≥2.12.0 – ≤2.12.5 |
| linkerd | linkerd | 2.13.0 | any |
| linkerd | linkerd | 2.13.1 | any |
| linkerd | linkerd | 2.14.0 | any |
| linkerd | linkerd | 2.14.1 | any |
| linecorp | armeria | * | <1.26.0 |
| redhat | 3scale_api_management_platform | 2.0 | any |
| redhat | advanced_cluster_management_for_kubernetes | 2.0 | any |
| redhat | advanced_cluster_security | 3.0 | any |
| redhat | advanced_cluster_security | 4.0 | any |
| redhat | ansible_automation_platform | 2.0 | any |
| redhat | build_of_optaplanner | 8.0 | any |
| redhat | build_of_quarkus | * | any |
| redhat | ceph_storage | 5.0 | any |
| redhat | cert-manager_operator_for_red_hat_openshift | * | any |
| redhat | certification_for_red_hat_enterprise_linux | 8.0 | any |
| redhat | certification_for_red_hat_enterprise_linux | 9.0 | any |
| redhat | cost_management | * | any |
| redhat | cryostat | 2.0 | any |
| redhat | decision_manager | 7.0 | any |
| redhat | fence_agents_remediation_operator | * | any |
| redhat | integration_camel_for_spring_boot | * | any |
| redhat | integration_camel_k | * | any |
| redhat | integration_service_registry | * | any |
| redhat | jboss_a-mq | 7 | any |
| redhat | jboss_a-mq_streams | * | any |
| redhat | jboss_core_services | * | any |
| redhat | jboss_data_grid | 7.0.0 | any |
| redhat | jboss_enterprise_application_platform | 6.0.0 | any |
| redhat | jboss_enterprise_application_platform | 7.0.0 | any |
| redhat | jboss_fuse | 6.0.0 | any |
| redhat | jboss_fuse | 7.0.0 | any |
| redhat | logging_subsystem_for_red_hat_openshift | * | any |
| redhat | machine_deletion_remediation_operator | * | any |
| redhat | migration_toolkit_for_applications | 6.0 | any |
| redhat | migration_toolkit_for_containers | * | any |
| redhat | migration_toolkit_for_virtualization | * | any |
| redhat | network_observability_operator | * | any |
| redhat | node_healthcheck_operator | * | any |
| redhat | node_maintenance_operator | * | any |
| redhat | openshift | * | any |
| redhat | openshift_api_for_data_protection | * | any |
| redhat | openshift_container_platform | 4.0 | any |
| redhat | openshift_container_platform_assisted_installer | * | any |
| redhat | openshift_data_science | * | any |
| redhat | openshift_dev_spaces | * | any |
| redhat | openshift_developer_tools_and_services | * | any |
| redhat | openshift_distributed_tracing | * | any |
| redhat | openshift_gitops | * | any |
| redhat | openshift_pipelines | * | any |
| redhat | openshift_sandboxed_containers | * | any |
| redhat | openshift_secondary_scheduler_operator | * | any |
| redhat | openshift_serverless | * | any |
| redhat | openshift_service_mesh | 2.0 | any |
| redhat | openshift_virtualization | 4 | any |
| redhat | openstack_platform | 16.1 | any |
| redhat | openstack_platform | 16.2 | any |
| redhat | openstack_platform | 17.1 | any |
| redhat | process_automation | 7.0 | any |
| redhat | quay | 3.0.0 | any |
| redhat | run_once_duration_override_operator | * | any |
| redhat | satellite | 6.0 | any |
| redhat | self_node_remediation_operator | * | any |
| redhat | service_interconnect | 1.0 | any |
| redhat | single_sign-on | 7.0 | any |
| redhat | support_for_spring_boot | * | any |
| redhat | web_terminal | * | any |
| redhat | enterprise_linux | 6.0 | any |
| redhat | enterprise_linux | 8.0 | any |
| redhat | enterprise_linux | 9.0 | any |
| redhat | service_telemetry_framework | 1.5 | any |
| redhat | enterprise_linux | 8.0 | any |
| fedoraproject | fedora | 37 | any |
| fedoraproject | fedora | 38 | any |
| netapp | astra_control_center | * | any |
| netapp | oncommand_insight | * | any |
| akka | http_server | * | <10.5.3 |
| konghq | kong_gateway | * | <3.4.2 |
| jenkins | jenkins | * | ≤2.414.2 |
| jenkins | jenkins | * | ≤2.427 |
| apache | solr | * | <9.4.0 |
| openresty | openresty | * | <1.21.4.3 |
| cisco | business_process_automation | * | <3.2.003.009 |
| cisco | connected_mobile_experiences | * | <11.1 |
| cisco | crosswork_data_gateway | * | <4.1.3 |
| cisco | crosswork_data_gateway | * | ≥5.0.0 – <5.0.2 |
| cisco | crosswork_situation_manager | * | any |
| cisco | crosswork_zero_touch_provisioning | * | <6.0.0 |
| cisco | data_center_network_manager | * | any |
| cisco | enterprise_chat_and_email | * | any |
| cisco | expressway | * | <x14.3.3 |
| cisco | firepower_threat_defense | * | <7.4.2 |
| cisco | iot_field_network_director | * | <4.11.0 |
| cisco | prime_access_registrar | * | <9.3.3 |
| cisco | prime_cable_provisioning | * | <7.2.1 |
| cisco | prime_infrastructure | * | <3.10.4 |
| cisco | prime_network_registrar | * | <11.2 |
| cisco | secure_dynamic_attributes_connector | * | <2.2.0 |
| cisco | secure_malware_analytics | * | <2.19.2 |
| cisco | telepresence_video_communication_server | * | <x14.3.3 |
| cisco | ultra_cloud_core_-_policy_control_function | * | <2024.01.0 |
| cisco | ultra_cloud_core_-_policy_control_function | 2024.01.0 | any |
| cisco | ultra_cloud_core_-_serving_gateway_function | * | <2024.02.0 |
| cisco | ultra_cloud_core_-_session_management_function | * | <2024.02.0 |
| cisco | unified_attendant_console_advanced | * | any |
| cisco | unified_contact_center_domain_manager | * | any |
| cisco | unified_contact_center_enterprise | * | any |
| cisco | unified_contact_center_enterprise_-_live_data_server | * | <12.6.2 |
| cisco | unified_contact_center_management_portal | * | any |
| cisco | fog_director | * | <1.22 |
| cisco | ios_xe | * | <17.15.1 |
| cisco | ios_xr | * | <7.11.2 |
| cisco | secure_web_appliance_firmware | * | <15.1.0 |
| cisco | secure_web_appliance | * | any |
| cisco | nx-os | * | <10.2\(7\) |
| cisco | nx-os | * | ≥10.3\(1\) – <10.3\(5\) |
| cisco | nx-os | * | ≥10.4\(1\) – <10.4\(2\) |
| cisco | nexus_3016 | * | any |
| cisco | nexus_3016q | * | any |
| cisco | nexus_3048 | * | any |
| cisco | nexus_3064 | * | any |
| cisco | nexus_3064-32t | * | any |
| cisco | nexus_3064-t | * | any |
| cisco | nexus_3064-x | * | any |
| cisco | nexus_3064t | * | any |
| cisco | nexus_3064x | * | any |
| cisco | nexus_3100 | * | any |
| cisco | nexus_3100-v | * | any |
| cisco | nexus_3100-z | * | any |
| cisco | nexus_3100v | * | any |
| cisco | nexus_31108pc-v | * | any |
| cisco | nexus_31108pv-v | * | any |
| cisco | nexus_31108tc-v | * | any |
| cisco | nexus_31128pq | * | any |
| cisco | nexus_3132c-z | * | any |
| cisco | nexus_3132q | * | any |
| cisco | nexus_3132q-v | * | any |
| cisco | nexus_3132q-x | * | any |
| cisco | nexus_3132q-x\/3132q-xl | * | any |
| cisco | nexus_3132q-xl | * | any |
| cisco | nexus_3164q | * | any |
| cisco | nexus_3172 | * | any |
| cisco | nexus_3172pq | * | any |
| cisco | nexus_3172pq-xl | * | any |
| cisco | nexus_3172pq\/pq-xl | * | any |
| cisco | nexus_3172tq | * | any |
| cisco | nexus_3172tq-32t | * | any |
| cisco | nexus_3172tq-xl | * | any |
| cisco | nexus_3200 | * | any |
| cisco | nexus_3232 | * | any |
| cisco | nexus_3232c | * | any |
| cisco | nexus_3232c_ | * | any |
| cisco | nexus_3264c-e | * | any |
| cisco | nexus_3264q | * | any |
| cisco | nexus_3400 | * | any |
| cisco | nexus_3408-s | * | any |
| cisco | nexus_34180yc | * | any |
| cisco | nexus_34200yc-sm | * | any |
| cisco | nexus_3432d-s | * | any |
| cisco | nexus_3464c | * | any |
| cisco | nexus_3500 | * | any |
| cisco | nexus_3524 | * | any |
| cisco | nexus_3524-x | * | any |
| cisco | nexus_3524-x\/xl | * | any |
| cisco | nexus_3524-xl | * | any |
| cisco | nexus_3548 | * | any |
| cisco | nexus_3548-x | * | any |
| cisco | nexus_3548-x\/xl | * | any |
| cisco | nexus_3548-xl | * | any |
| cisco | nexus_3600 | * | any |
| cisco | nexus_36180yc-r | * | any |
| cisco | nexus_3636c-r | * | any |
| cisco | nx-os | * | <10.2\(7\) |
| cisco | nx-os | * | ≥10.3\(1\) – <10.3\(5\) |
| cisco | nx-os | * | ≥10.4\(1\) – <10.4\(2\) |
| cisco | nexus_9000v | * | any |
| cisco | nexus_9200 | * | any |
| cisco | nexus_9200yc | * | any |
| cisco | nexus_92160yc-x | * | any |
| cisco | nexus_92160yc_switch | * | any |
| cisco | nexus_9221c | * | any |
| cisco | nexus_92300yc | * | any |
| cisco | nexus_92300yc_switch | * | any |
| cisco | nexus_92304qc | * | any |
| cisco | nexus_92304qc_switch | * | any |
| cisco | nexus_9232e | * | any |
| cisco | nexus_92348gc-x | * | any |
| cisco | nexus_9236c | * | any |
| cisco | nexus_9236c_switch | * | any |
| cisco | nexus_9272q | * | any |
| cisco | nexus_9272q_switch | * | any |
| cisco | nexus_9300 | * | any |
| cisco | nexus_93108tc-ex | * | any |
| cisco | nexus_93108tc-ex-24 | * | any |
| cisco | nexus_93108tc-ex_switch | * | any |
| cisco | nexus_93108tc-fx | * | any |
| cisco | nexus_93108tc-fx-24 | * | any |
| cisco | nexus_93108tc-fx3h | * | any |
| cisco | nexus_93108tc-fx3p | * | any |
| cisco | nexus_93120tx | * | any |
| cisco | nexus_93120tx_switch | * | any |
| cisco | nexus_93128 | * | any |
| cisco | nexus_93128tx | * | any |
| cisco | nexus_93128tx_switch | * | any |
| cisco | nexus_9316d-gx | * | any |
| cisco | nexus_93180lc-ex | * | any |
| cisco | nexus_93180lc-ex_switch | * | any |
| cisco | nexus_93180tc-ex | * | any |
| cisco | nexus_93180yc-ex | * | any |
| cisco | nexus_93180yc-ex-24 | * | any |
| cisco | nexus_93180yc-ex_switch | * | any |
| cisco | nexus_93180yc-fx | * | any |
| cisco | nexus_93180yc-fx-24 | * | any |
| cisco | nexus_93180yc-fx3 | * | any |
| cisco | nexus_93180yc-fx3h | * | any |
| cisco | nexus_93180yc-fx3s | * | any |
| cisco | nexus_93216tc-fx2 | * | any |
| cisco | nexus_93240tc-fx2 | * | any |
| cisco | nexus_93240yc-fx2 | * | any |
| cisco | nexus_9332c | * | any |
| cisco | nexus_9332d-gx2b | * | any |
| cisco | nexus_9332d-h2r | * | any |
| cisco | nexus_9332pq | * | any |
| cisco | nexus_9332pq_switch | * | any |
| cisco | nexus_93360yc-fx2 | * | any |
| cisco | nexus_9336c-fx2 | * | any |
| cisco | nexus_9336c-fx2-e | * | any |
| cisco | nexus_9336pq | * | any |
| cisco | nexus_9336pq_aci | * | any |
| cisco | nexus_9336pq_aci_spine | * | any |
| cisco | nexus_9336pq_aci_spine_switch | * | any |
| cisco | nexus_9348d-gx2a | * | any |
| cisco | nexus_9348gc-fx3 | * | any |
| cisco | nexus_9348gc-fxp | * | any |
| cisco | nexus_93600cd-gx | * | any |
| cisco | nexus_9364c | * | any |
| cisco | nexus_9364c-gx | * | any |
| cisco | nexus_9364d-gx2a | * | any |
| cisco | nexus_9372px | * | any |
| cisco | nexus_9372px-e | * | any |
| cisco | nexus_9372px-e_switch | * | any |
| cisco | nexus_9372px_switch | * | any |
| cisco | nexus_9372tx | * | any |
| cisco | nexus_9372tx-e | * | any |
| cisco | nexus_9372tx-e_switch | * | any |
| cisco | nexus_9372tx_switch | * | any |
| cisco | nexus_9396px | * | any |
| cisco | nexus_9396px_switch | * | any |
| cisco | nexus_9396tx | * | any |
| cisco | nexus_9396tx_switch | * | any |
| cisco | nexus_9408 | * | any |
| cisco | nexus_9432pq | * | any |
| cisco | nexus_9500 | * | any |
| cisco | nexus_9500_16-slot | * | any |
| cisco | nexus_9500_4-slot | * | any |
| cisco | nexus_9500_8-slot | * | any |
| cisco | nexus_9500_supervisor_a | * | any |
| cisco | nexus_9500_supervisor_a\+ | * | any |
| cisco | nexus_9500_supervisor_b | * | any |
| cisco | nexus_9500_supervisor_b\+ | * | any |
| cisco | nexus_9500r | * | any |
| cisco | nexus_9504 | * | any |
| cisco | nexus_9504_switch | * | any |
| cisco | nexus_9508 | * | any |
| cisco | nexus_9508_switch | * | any |
| cisco | nexus_9516 | * | any |
| cisco | nexus_9516_switch | * | any |
| cisco | nexus_9536pq | * | any |
| cisco | nexus_9636pq | * | any |
| cisco | nexus_9716d-gx | * | any |
| cisco | nexus_9736pq | * | any |
| cisco | nexus_9800 | * | any |
| cisco | nexus_9804 | * | any |
| cisco | nexus_9808 | * | any |
References 173
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/10/6
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/10/7
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/13/4
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/13/9
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/18/4
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/18/8
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/19/6
- openwall.com http://www.openwall.com/lists/oss-security/2023/10/20/8
- openwall.com http://www.openwall.com/lists/oss-security/2025/08/13/6
- access.redhat.com https://access.redhat.com/security/cve/cve-2023-44487
- arstechnica.com https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
- aws.amazon.com https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
- blog.cloudflare.com https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- blog.cloudflare.com https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- blog.litespeedtech.com https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
- blog.qualys.com https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
- blog.vespa.ai https://blog.vespa.ai/cve-2023-44487/
- bugzilla.proxmox.com https://bugzilla.proxmox.com/show_bug.cgi?id=4988
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2242803
- bugzilla.suse.com https://bugzilla.suse.com/show_bug.cgi?id=1216123
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-341067.html
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-784301.html
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-832273.html
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-915275.html
- cgit.freebsd.org https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
- cloud.google.com https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
- cloud.google.com https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
- community.traefik.io https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
- discuss.hashicorp.com https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715
- edg.io https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
- forums.swift.org https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764
- gist.github.com https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
- github.com https://github.com/Azure/AKS/issues/3947
- github.com https://github.com/Kong/kong/discussions/11741
- github.com https://github.com/advisories/GHSA-qppj-fm5r-hxr3
- github.com https://github.com/advisories/GHSA-vx74-f528-fxqg
- github.com https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
- github.com https://github.com/akka/akka-http/issues/4323
- github.com https://github.com/alibaba/tengine/issues/1872
- github.com https://github.com/apache/apisix/issues/10320
- github.com https://github.com/apache/httpd-site/pull/10
- github.com https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113
- github.com https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2
- github.com https://github.com/apache/trafficserver/pull/10564
- github.com https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
- github.com https://github.com/bcdannyboy/CVE-2023-44487
- github.com https://github.com/caddyserver/caddy/issues/5877
- github.com https://github.com/caddyserver/caddy/releases/tag/v2.7.5
- github.com https://github.com/dotnet/announcements/issues/277
- github.com https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73
- github.com https://github.com/eclipse/jetty.project/issues/10679
- github.com https://github.com/envoyproxy/envoy/pull/30055
- github.com https://github.com/etcd-io/etcd/issues/16740
- github.com https://github.com/facebook/proxygen/pull/466
- github.com https://github.com/golang/go/issues/63417
- github.com https://github.com/grpc/grpc-go/pull/6703
- github.com https://github.com/grpc/grpc/releases/tag/v1.59.2
- github.com https://github.com/h2o/h2o/pull/3291
- github.com https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
- github.com https://github.com/haproxy/haproxy/issues/2312
- github.com https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244
- github.com https://github.com/junkurihara/rust-rpxy/issues/97
- github.com https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1
- github.com https://github.com/kazu-yamamoto/http2/issues/93
- github.com https://github.com/kubernetes/kubernetes/pull/121120
- github.com https://github.com/line/armeria/pull/5232
- github.com https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632
- github.com https://github.com/micrictor/http2-rst-stream
- github.com https://github.com/microsoft/CBL-Mariner/pull/6381
- github.com https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
- github.com https://github.com/nghttp2/nghttp2/pull/1961
- github.com https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
- github.com https://github.com/ninenines/cowboy/issues/1615
- github.com https://github.com/nodejs/node/pull/50121
- github.com https://github.com/openresty/openresty/issues/930
- github.com https://github.com/opensearch-project/data-prepper/issues/3474
- github.com https://github.com/oqtane/oqtane.framework/discussions/3367
- github.com https://github.com/projectcontour/contour/pull/5826
- github.com https://github.com/tempesta-tech/tempesta/issues/1986
- github.com https://github.com/varnishcache/varnish-cache/issues/3996
- groups.google.com https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
- istio.io https://istio.io/latest/news/security/istio-security-2023-004/
- linkerd.io https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
- lists.apache.org https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/
- lists.w3.org https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html
- mailman.nginx.org https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
- martinthomson.github.io https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html
- msrc.microsoft.com https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
- msrc.microsoft.com https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
- my.f5.com https://my.f5.com/manage/s/article/K000137106
- netty.io https://netty.io/news/2023/10/10/4-1-100-Final.html
- news.ycombinator.com https://news.ycombinator.com/item?id=37830987
- news.ycombinator.com https://news.ycombinator.com/item?id=37830998
- news.ycombinator.com https://news.ycombinator.com/item?id=37831062
- news.ycombinator.com https://news.ycombinator.com/item?id=37837043
- openssf.org https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/
- seanmonstar.com https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected
- sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ
- security.gentoo.org https://security.gentoo.org/glsa/202311-09
- security.netapp.com https://security.netapp.com/advisory/ntap-20231016-0001/
- security.netapp.com https://security.netapp.com/advisory/ntap-20240426-0007/
- security.netapp.com https://security.netapp.com/advisory/ntap-20240621-0006/
- security.netapp.com https://security.netapp.com/advisory/ntap-20240621-0007/
- security.paloaltonetworks.com https://security.paloaltonetworks.com/CVE-2023-44487
- tomcat.apache.org https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
- ubuntu.com https://ubuntu.com/security/CVE-2023-44487
- bleepingcomputer.com https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/
- cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487
- cisa.gov https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
- darkreading.com https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event
- debian.org https://www.debian.org/security/2023/dsa-5521
- debian.org https://www.debian.org/security/2023/dsa-5522
- debian.org https://www.debian.org/security/2023/dsa-5540
- debian.org https://www.debian.org/security/2023/dsa-5549
- debian.org https://www.debian.org/security/2023/dsa-5558
- debian.org https://www.debian.org/security/2023/dsa-5570
- haproxy.com https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
- netlify.com https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
- nginx.com https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
- openwall.com https://www.openwall.com/lists/oss-security/2023/10/10/6
- phoronix.com https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack
- theregister.com https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
- vicarius.io https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause
Remediation
- cgit.freebsd.org https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
- gist.github.com https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
- github.com https://github.com/advisories/GHSA-vx74-f528-fxqg
- github.com https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
- github.com https://github.com/apache/trafficserver/pull/10564
- github.com https://github.com/envoyproxy/envoy/pull/30055
- github.com https://github.com/etcd-io/etcd/issues/16740
- github.com https://github.com/facebook/proxygen/pull/466
- github.com https://github.com/grpc/grpc-go/pull/6703
- github.com https://github.com/h2o/h2o/pull/3291
- github.com https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1
- github.com https://github.com/kubernetes/kubernetes/pull/121120
- github.com https://github.com/line/armeria/pull/5232
- github.com https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632
- github.com https://github.com/microsoft/CBL-Mariner/pull/6381
- github.com https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
- github.com https://github.com/nghttp2/nghttp2/pull/1961
- github.com https://github.com/opensearch-project/data-prepper/issues/3474
- github.com https://github.com/projectcontour/contour/pull/5826
- mailman.nginx.org https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
- msrc.microsoft.com https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
- msrc.microsoft.com https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487