CVE-2023-44487
HTTP/2 Rapid Reset Attack Vulnerability
CVSS
7.5
Alto
EPSS
100.0%
p100
KEV
SÍ
10 oct 2023
Exploit Today
80
0-100
Publicado: 10 oct 2023 · Última mod.: 11 ago 2026 · CWE-400
Producto
IETF / HTTP/2
Vulnerabilidad
HTTP/2 Rapid Reset Attack Vulnerability
Añadido a KEV
10 oct 2023
Remediar antes de
31 oct 2023
Uso conocido en ransomware
No
Descripción resumida
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Acción requerida
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notas
This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/10/6
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/10/7
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/13/4
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/13/9
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/18/4
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/18/8
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/19/6
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2023/10/20/8
- access.redhat.comhttps://access.redhat.com/security/cve/cve-2023-44487
- arstechnica.comhttps://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
- aws.amazon.comhttps://aws.amazon.com/security/security-bulletins/AWS-2023-011/
- blog.cloudflare.comhttps://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- blog.cloudflare.comhttps://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- blog.litespeedtech.comhttps://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
- blog.qualys.comhttps://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
- blog.vespa.aihttps://blog.vespa.ai/cve-2023-44487/
- bugzilla.proxmox.comhttps://bugzilla.proxmox.com/show_bug.cgi?id=4988
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- bugzilla.suse.comhttps://bugzilla.suse.com/show_bug.cgi?id=1216123
- cgit.freebsd.orghttps://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9