CVE-2023-44487KEV Β· OVERDUECWE-400denial-of-service

HTTP/2 Rapid Reset Attack Vulnerability

High Β· published October 10, 2023

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.5. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1041
days past CISA
deadline
CVSS v3.1
7.5
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A crafty request cancellation can lead to a server resource drain faster than you can say "HTTP/2!" ⚑️ Think of it like a chaotic restaurant where customers keep canceling their orders at the last minute β€” the kitchen gets swamped trying to process new requests while still juggling the old ones, leading to a complete standstill! If an attacker exploits this vulnerability, they could quickly overwhelm your server, causing significant downtime and service interruptions. This could lead to all sorts of chaos, from frustrated users to potential revenue loss as your site becomes inaccessible. It's a situation you definitely want to avoid!

Put simply

Think of it like a chaotic restaurant where customers keep canceling their orders at the last minute β€” the kitchen gets swamped trying to process new requests while still juggling the old ones, leading to a complete standstill! CVE-2023-44487 in the HTTP/2 protocol allows an attacker to reset multiple streams by rapidly canceling requests, leading to excessive resource consumption and potential denial of service.

What to do

If an attacker exploits this vulnerability, they could quickly overwhelm your server, causing significant downtime and service interruptions. This could lead to all sorts of chaos, from frustrated users to potential revenue loss as your site becomes inaccessible. It's a situation you definitely want to avoid! To protect your servers, ensure you're running the latest version of your web server software that addresses this vulnerability. Additionally, consider implementing rate limiting on requests to help mitigate rapid-fire cancellation attacks. Regularly monitor your server performance to catch any abnormal spikes early! You've got this! Tackle the issue head-on and keep your server running smoothly! πŸ›‘οΈ

The record
Technical detail
CVSS v3.1
7.5 Β· HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 Β· 100.0th percentile
Weakness
CWE-400 Β· Uncontrolled Resource Consumption
Published
2023-10-10T18:15Z
KEV added
2023-10-10 Β· due 2023-10-31
Affected products (304)
ProductVersionsFixed in
siemens/simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmwareβ‰₯ 3.1.5β€”
siemens/sinec_ins< 1.01.0
siemens/sinec_insall versionsβ€”
siemens/sinec_insall versionsβ€”
siemens/sinec_insall versionsβ€”
siemens/sinec_insall versionsβ€”
siemens/sinec_insall versionsβ€”
siemens/sinec_nms< 3.03.0
siemens/st7_scadaconnect< 1.11.1
siemens/ruggedcom_ape1808_firmwareall versionsβ€”
siemens/simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmwareβ‰₯ 3.1.5β€”
siemens/siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmwareβ‰₯ 3.1.5β€”
ietf/httpall versionsβ€”
nghttp2/nghttp2< 1.57.01.57.0
netty/netty< 4.1.1004.1.100
envoyproxy/envoyall versionsβ€”
envoyproxy/envoyall versionsβ€”
envoyproxy/envoyall versionsβ€”
envoyproxy/envoyall versionsβ€”
eclipse/jetty< 9.4.539.4.53
eclipse/jettyβ‰₯ 10.0.0, < 10.0.1710.0.17
eclipse/jettyβ‰₯ 11.0.0, < 11.0.1711.0.17
eclipse/jettyβ‰₯ 12.0.0, < 12.0.212.0.2
caddyserver/caddy< 2.7.52.7.5
golang/go< 1.20.101.20.10
golang/goβ‰₯ 1.21.0, < 1.21.31.21.3
golang/http2< 0.17.00.17.0
golang/networking< 0.17.00.17.0
f5/big-ip_access_policy_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_access_policy_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_access_policy_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_access_policy_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_access_policy_managerall versionsβ€”
f5/big-ip_advanced_firewall_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_advanced_firewall_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_advanced_firewall_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_advanced_firewall_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_advanced_firewall_managerall versionsβ€”
f5/big-ip_advanced_web_application_firewallβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_advanced_web_application_firewallβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_advanced_web_application_firewallβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_advanced_web_application_firewallβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_advanced_web_application_firewallall versionsβ€”
f5/big-ip_analyticsβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_analyticsβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_analyticsβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_analyticsβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_analyticsall versionsβ€”
f5/big-ip_application_acceleration_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_application_acceleration_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_application_acceleration_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_application_acceleration_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_application_acceleration_managerall versionsβ€”
f5/big-ip_application_security_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_application_security_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_application_security_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_application_security_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_application_security_managerall versionsβ€”
f5/big-ip_application_visibility_and_reportingβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_application_visibility_and_reportingβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_application_visibility_and_reportingβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_application_visibility_and_reportingβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_application_visibility_and_reportingall versionsβ€”
f5/big-ip_carrier-grade_natβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_carrier-grade_natβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_carrier-grade_natβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_carrier-grade_natβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_carrier-grade_natall versionsβ€”
f5/big-ip_ddos_hybrid_defenderβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_ddos_hybrid_defenderβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_ddos_hybrid_defenderβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_ddos_hybrid_defenderβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_ddos_hybrid_defenderall versionsβ€”
f5/big-ip_domain_name_systemβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_domain_name_systemβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_domain_name_systemβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_domain_name_systemβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_domain_name_systemall versionsβ€”
f5/big-ip_fraud_protection_serviceβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_fraud_protection_serviceβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_fraud_protection_serviceβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_fraud_protection_serviceβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_fraud_protection_serviceall versionsβ€”
f5/big-ip_global_traffic_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_global_traffic_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_global_traffic_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_global_traffic_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_global_traffic_managerall versionsβ€”
f5/big-ip_link_controllerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_link_controllerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_link_controllerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_link_controllerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_link_controllerall versionsβ€”
f5/big-ip_local_traffic_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_local_traffic_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_local_traffic_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_local_traffic_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_local_traffic_managerall versionsβ€”
f5/big-ip_nextall versionsβ€”
f5/big-ip_next_service_proxy_for_kubernetesβ‰₯ 1.5.0, ≀ 1.8.2β€”
f5/big-ip_policy_enforcement_managerβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_policy_enforcement_managerβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_policy_enforcement_managerβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_policy_enforcement_managerβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_policy_enforcement_managerall versionsβ€”
f5/big-ip_ssl_orchestratorβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_ssl_orchestratorβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_ssl_orchestratorβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_ssl_orchestratorβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_ssl_orchestratorall versionsβ€”
f5/big-ip_webacceleratorβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_webacceleratorβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_webacceleratorβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_webacceleratorβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_webacceleratorall versionsβ€”
f5/big-ip_websafeβ‰₯ 13.1.0, ≀ 13.1.5β€”
f5/big-ip_websafeβ‰₯ 14.1.0, ≀ 14.1.5β€”
f5/big-ip_websafeβ‰₯ 15.1.0, ≀ 15.1.10β€”
f5/big-ip_websafeβ‰₯ 16.1.0, ≀ 16.1.4β€”
f5/big-ip_websafeall versionsβ€”
f5/nginxβ‰₯ 1.9.5, ≀ 1.25.2β€”
f5/nginx_ingress_controllerβ‰₯ 2.0.0, ≀ 2.4.2β€”
f5/nginx_ingress_controllerβ‰₯ 3.0.0, ≀ 3.3.0β€”
f5/nginx_plusβ‰₯ r25, < r29r29
f5/nginx_plusall versionsβ€”
f5/nginx_plusall versionsβ€”
apache/tomcatβ‰₯ 8.5.0, ≀ 8.5.93β€”
apache/tomcatβ‰₯ 9.0.0, ≀ 9.0.80β€”
apache/tomcatβ‰₯ 10.1.0, ≀ 10.1.13β€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apache/tomcatall versionsβ€”
apple/swiftnio_http\/2< 1.28.01.28.0
grpc/grpc< 1.56.31.56.3
grpc/grpc≀ 1.59.2β€”
grpc/grpcβ‰₯ 1.58.0, < 1.58.31.58.3
grpc/grpcall versionsβ€”
microsoft/.netβ‰₯ 6.0.0, < 6.0.236.0.23
microsoft/.netβ‰₯ 7.0.0, < 7.0.127.0.12
microsoft/asp.net_coreβ‰₯ 6.0.0, < 6.0.236.0.23
microsoft/asp.net_coreβ‰₯ 7.0.0, < 7.0.127.0.12
microsoft/azure_kubernetes_service< 2023-10-082023-10-08
microsoft/visual_studio_2022β‰₯ 17.0, < 17.2.2017.2.20
microsoft/visual_studio_2022β‰₯ 17.4, < 17.4.1217.4.12
microsoft/visual_studio_2022β‰₯ 17.6, < 17.6.817.6.8
microsoft/visual_studio_2022β‰₯ 17.7, < 17.7.517.7.5
microsoft/windows_10_1607< 10.0.14393.635110.0.14393.6351
microsoft/windows_10_1607< 10.0.14393.635110.0.14393.6351
microsoft/windows_10_1809< 10.0.17763.497410.0.17763.4974
microsoft/windows_10_21h2< 10.0.19044.357010.0.19044.3570
microsoft/windows_10_22h2< 10.0.19045.357010.0.19045.3570
microsoft/windows_11_21h2< 10.0.22000.253810.0.22000.2538
microsoft/windows_11_22h2< 10.0.22621.242810.0.22621.2428
microsoft/windows_server_2016all versionsβ€”
microsoft/windows_server_2019all versionsβ€”
microsoft/windows_server_2022all versionsβ€”
nodejs/node.jsβ‰₯ 18.0.0, < 18.18.218.18.2
nodejs/node.jsβ‰₯ 20.0.0, < 20.8.120.8.1
microsoft/cbl-mariner< 2023-10-112023-10-11
dena/h2o< 2023-10-102023-10-10
facebook/proxygen< 2023.10.16.002023.10.16.00
apache/apisix< 3.6.13.6.1
apache/traffic_serverβ‰₯ 8.0.0, < 8.1.98.1.9
apache/traffic_serverβ‰₯ 9.0.0, < 9.2.39.2.3
amazon/opensearch_data_prepper< 2.5.02.5.0
debian/debian_linuxall versionsβ€”
debian/debian_linuxall versionsβ€”
debian/debian_linuxall versionsβ€”
kazu-yamamoto/http2< 4.2.24.2.2
istio/istio< 1.17.61.17.6
istio/istioβ‰₯ 1.18.0, < 1.18.31.18.3
istio/istioβ‰₯ 1.19.0, < 1.19.11.19.1
varnish_cache_project/varnish_cache< 2023-10-102023-10-10
traefik/traefik< 2.10.52.10.5
traefik/traefikall versionsβ€”
traefik/traefikall versionsβ€”
traefik/traefikall versionsβ€”
projectcontour/contour< 2023-10-112023-10-11
linkerd/linkerdβ‰₯ 2.12.0, ≀ 2.12.5β€”
linkerd/linkerdall versionsβ€”
linkerd/linkerdall versionsβ€”
linkerd/linkerdall versionsβ€”
linkerd/linkerdall versionsβ€”
linecorp/armeria< 1.26.01.26.0
redhat/3scale_api_management_platformall versionsβ€”
redhat/advanced_cluster_management_for_kubernetesall versionsβ€”
redhat/advanced_cluster_securityall versionsβ€”
redhat/advanced_cluster_securityall versionsβ€”
redhat/ansible_automation_platformall versionsβ€”
redhat/build_of_optaplannerall versionsβ€”
redhat/build_of_quarkusall versionsβ€”
redhat/ceph_storageall versionsβ€”
redhat/cert-manager_operator_for_red_hat_openshiftall versionsβ€”
redhat/certification_for_red_hat_enterprise_linuxall versionsβ€”
redhat/certification_for_red_hat_enterprise_linuxall versionsβ€”
redhat/cost_managementall versionsβ€”
redhat/cryostatall versionsβ€”
redhat/decision_managerall versionsβ€”
redhat/fence_agents_remediation_operatorall versionsβ€”
redhat/integration_camel_for_spring_bootall versionsβ€”
redhat/integration_camel_kall versionsβ€”
redhat/integration_service_registryall versionsβ€”
redhat/jboss_a-mqall versionsβ€”
redhat/jboss_a-mq_streamsall versionsβ€”
redhat/jboss_core_servicesall versionsβ€”
redhat/jboss_data_gridall versionsβ€”
redhat/jboss_enterprise_application_platformall versionsβ€”
redhat/jboss_enterprise_application_platformall versionsβ€”
redhat/jboss_fuseall versionsβ€”
redhat/jboss_fuseall versionsβ€”
redhat/logging_subsystem_for_red_hat_openshiftall versionsβ€”
redhat/machine_deletion_remediation_operatorall versionsβ€”
redhat/migration_toolkit_for_applicationsall versionsβ€”
redhat/migration_toolkit_for_containersall versionsβ€”
redhat/migration_toolkit_for_virtualizationall versionsβ€”
redhat/network_observability_operatorall versionsβ€”
redhat/node_healthcheck_operatorall versionsβ€”
redhat/node_maintenance_operatorall versionsβ€”
redhat/openshiftall versionsβ€”
redhat/openshift_api_for_data_protectionall versionsβ€”
redhat/openshift_container_platformall versionsβ€”
redhat/openshift_container_platform_assisted_installerall versionsβ€”
redhat/openshift_data_scienceall versionsβ€”
redhat/openshift_dev_spacesall versionsβ€”
redhat/openshift_developer_tools_and_servicesall versionsβ€”
redhat/openshift_distributed_tracingall versionsβ€”
redhat/openshift_gitopsall versionsβ€”
redhat/openshift_pipelinesall versionsβ€”
redhat/openshift_sandboxed_containersall versionsβ€”
redhat/openshift_secondary_scheduler_operatorall versionsβ€”
redhat/openshift_serverlessall versionsβ€”
redhat/openshift_service_meshall versionsβ€”
redhat/openshift_virtualizationall versionsβ€”
redhat/openstack_platformall versionsβ€”
redhat/openstack_platformall versionsβ€”
redhat/openstack_platformall versionsβ€”
redhat/process_automationall versionsβ€”
redhat/quayall versionsβ€”
redhat/run_once_duration_override_operatorall versionsβ€”
redhat/satelliteall versionsβ€”
redhat/self_node_remediation_operatorall versionsβ€”
redhat/service_interconnectall versionsβ€”
redhat/single_sign-onall versionsβ€”
redhat/support_for_spring_bootall versionsβ€”
redhat/web_terminalall versionsβ€”
redhat/enterprise_linuxall versionsβ€”
redhat/enterprise_linuxall versionsβ€”
redhat/enterprise_linuxall versionsβ€”
redhat/service_telemetry_frameworkall versionsβ€”
fedoraproject/fedoraall versionsβ€”
fedoraproject/fedoraall versionsβ€”
netapp/astra_control_centerall versionsβ€”
netapp/oncommand_insightall versionsβ€”
akka/http_server< 10.5.310.5.3
konghq/kong_gateway< 3.4.23.4.2
jenkins/jenkins≀ 2.414.2β€”
jenkins/jenkins≀ 2.427β€”
apache/solr< 9.4.09.4.0
openresty/openresty< 1.21.4.31.21.4.3
cisco/business_process_automation< 3.2.003.0093.2.003.009
cisco/connected_mobile_experiences< 11.111.1
cisco/crosswork_data_gateway< 4.1.34.1.3
cisco/crosswork_data_gatewayβ‰₯ 5.0.0, < 5.0.25.0.2
cisco/crosswork_situation_managerall versionsβ€”
cisco/crosswork_zero_touch_provisioning< 6.0.06.0.0
cisco/data_center_network_managerall versionsβ€”
cisco/enterprise_chat_and_emailall versionsβ€”
cisco/expressway< x14.3.3x14.3.3
cisco/iot_field_network_director< 4.11.04.11.0
cisco/prime_access_registrar< 9.3.39.3.3
cisco/prime_cable_provisioning< 7.2.17.2.1
cisco/prime_infrastructure< 3.10.43.10.4
cisco/prime_network_registrar< 11.211.2
cisco/secure_dynamic_attributes_connector< 2.2.02.2.0
cisco/secure_firewall_threat_defense< 7.4.27.4.2
cisco/secure_malware_analytics< 2.19.22.19.2
cisco/telepresence_video_communication_server< x14.3.3x14.3.3
cisco/ultra_cloud_core_-_policy_control_function< 2024.01.02024.01.0
cisco/ultra_cloud_core_-_policy_control_functionall versionsβ€”
cisco/ultra_cloud_core_-_serving_gateway_function< 2024.02.02024.02.0
cisco/ultra_cloud_core_-_session_management_function< 2024.02.02024.02.0
cisco/unified_attendant_console_advancedall versionsβ€”
cisco/unified_contact_center_domain_managerall versionsβ€”
cisco/unified_contact_center_enterpriseall versionsβ€”
cisco/unified_contact_center_enterprise_-_live_data_server< 12.6.212.6.2
cisco/unified_contact_center_management_portalall versionsβ€”
cisco/fog_director< 1.221.22
cisco/ios_xe< 17.15.117.15.1
cisco/ios_xr< 7.11.27.11.2
cisco/secure_web_appliance_firmware< 15.1.015.1.0
cisco/nx-os< 10.2\(7\)10.2\(7\)
cisco/nx-osβ‰₯ 10.3\(1\), < 10.3\(5\)10.3\(5\)
cisco/nx-osβ‰₯ 10.4\(1\), < 10.4\(2\)10.4\(2\)
cisco/nx-os< 10.2\(7\)10.2\(7\)
cisco/nx-osβ‰₯ 10.3\(1\), < 10.3\(5\)10.3\(5\)
cisco/nx-osβ‰₯ 10.4\(1\), < 10.4\(2\)10.4\(2\)
References (292)
http://www.openwall.com/lists/oss-security/2023/10/10/6 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/10/7 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/13/4 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/13/9 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/18/4 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/18/8 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/19/6 Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/20/8 Β· [email protected]https://access.redhat.com/security/cve/cve-2023-44487 Β· [email protected]https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/ Β· [email protected]https://aws.amazon.com/security/security-bulletins/AWS-2023-011/ Β· [email protected]https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/ Β· [email protected]https://github.com/micrictor/http2-rst-stream Β· [email protected]https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/ Β· [email protected]https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/ Β· [email protected]https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack Β· [email protected]https://blog.vespa.ai/cve-2023-44487/ Β· [email protected]https://bugzilla.proxmox.com/show_bug.cgi?id=4988 Β· [email protected]https://bugzilla.redhat.com/show_bug.cgi?id=2242803 Β· [email protected]https://bugzilla.suse.com/show_bug.cgi?id=1216123 Β· [email protected]https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9 Β· [email protected]https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/ Β· [email protected]https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack Β· [email protected]https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125 Β· [email protected]https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715 Β· [email protected]https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve Β· [email protected]https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764 Β· [email protected]https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088 Β· [email protected]https://github.com/Azure/AKS/issues/3947 Β· [email protected]https://github.com/Kong/kong/discussions/11741 Β· [email protected]https://github.com/advisories/GHSA-qppj-fm5r-hxr3 Β· [email protected]https://github.com/advisories/GHSA-vx74-f528-fxqg Β· [email protected]https://github.com/advisories/GHSA-xpw8-rcwv-8f8p Β· [email protected]https://github.com/akka/akka-http/issues/4323 Β· [email protected]https://github.com/alibaba/tengine/issues/1872 Β· [email protected]https://github.com/apache/apisix/issues/10320 Β· [email protected]https://github.com/apache/httpd-site/pull/10 Β· [email protected]https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113 Β· [email protected]https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2 Β· [email protected]https://github.com/apache/trafficserver/pull/10564 Β· [email protected]https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487 Β· [email protected]https://github.com/bcdannyboy/CVE-2023-44487 Β· [email protected]https://github.com/caddyserver/caddy/issues/5877 Β· [email protected]https://github.com/caddyserver/caddy/releases/tag/v2.7.5 Β· [email protected]https://github.com/dotnet/announcements/issues/277 Β· [email protected]https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73 Β· [email protected]https://github.com/eclipse/jetty.project/issues/10679 Β· [email protected]https://github.com/envoyproxy/envoy/pull/30055 Β· [email protected]https://github.com/etcd-io/etcd/issues/16740 Β· [email protected]https://github.com/facebook/proxygen/pull/466 Β· [email protected]https://github.com/golang/go/issues/63417 Β· [email protected]https://github.com/grpc/grpc-go/pull/6703 Β· [email protected]https://github.com/grpc/grpc/releases/tag/v1.59.2 Β· [email protected]https://github.com/h2o/h2o/pull/3291 Β· [email protected]https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf Β· [email protected]https://github.com/haproxy/haproxy/issues/2312 Β· [email protected]https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244 Β· [email protected]https://github.com/junkurihara/rust-rpxy/issues/97 Β· [email protected]https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1 Β· [email protected]https://github.com/kazu-yamamoto/http2/issues/93 Β· [email protected]https://github.com/kubernetes/kubernetes/pull/121120 Β· [email protected]https://github.com/line/armeria/pull/5232 Β· [email protected]https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632 Β· [email protected]https://github.com/microsoft/CBL-Mariner/pull/6381 Β· [email protected]https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61 Β· [email protected]https://github.com/nghttp2/nghttp2/pull/1961 Β· [email protected]https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0 Β· [email protected]https://github.com/ninenines/cowboy/issues/1615 Β· [email protected]https://github.com/nodejs/node/pull/50121 Β· [email protected]https://github.com/openresty/openresty/issues/930 Β· [email protected]https://github.com/opensearch-project/data-prepper/issues/3474 Β· [email protected]https://github.com/oqtane/oqtane.framework/discussions/3367 Β· [email protected]https://github.com/projectcontour/contour/pull/5826 Β· [email protected]https://github.com/tempesta-tech/tempesta/issues/1986 Β· [email protected]https://github.com/varnishcache/varnish-cache/issues/3996 Β· [email protected]https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo Β· [email protected]https://istio.io/latest/news/security/istio-security-2023-004/ Β· [email protected]https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/ Β· [email protected]https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html Β· [email protected]https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/ Β· [email protected]https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/ Β· [email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/ Β· [email protected]https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html Β· [email protected]https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html Β· [email protected]https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html Β· [email protected]https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/ Β· [email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487 Β· [email protected]https://my.f5.com/manage/s/article/K000137106 Β· [email protected]https://netty.io/news/2023/10/10/4-1-100-Final.html Β· [email protected]https://news.ycombinator.com/item?id=37830987 Β· [email protected]https://news.ycombinator.com/item?id=37830998 Β· [email protected]https://news.ycombinator.com/item?id=37831062 Β· [email protected]https://news.ycombinator.com/item?id=37837043 Β· [email protected]https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/ Β· [email protected]https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected Β· [email protected]https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ Β· [email protected]https://security.gentoo.org/glsa/202311-09 Β· [email protected]https://security.netapp.com/advisory/ntap-20231016-0001/ Β· [email protected]https://security.netapp.com/advisory/ntap-20240426-0007/ Β· [email protected]https://security.netapp.com/advisory/ntap-20240621-0006/ Β· [email protected]https://security.netapp.com/advisory/ntap-20240621-0007/ Β· [email protected]https://security.paloaltonetworks.com/CVE-2023-44487 Β· [email protected]https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14 Β· [email protected]https://ubuntu.com/security/CVE-2023-44487 Β· [email protected]https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/ Β· [email protected]https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 Β· [email protected]https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event Β· [email protected]https://www.debian.org/security/2023/dsa-5521 Β· [email protected]https://www.debian.org/security/2023/dsa-5522 Β· [email protected]https://www.debian.org/security/2023/dsa-5540 Β· [email protected]https://www.debian.org/security/2023/dsa-5549 Β· [email protected]https://www.debian.org/security/2023/dsa-5558 Β· [email protected]https://www.debian.org/security/2023/dsa-5570 Β· [email protected]https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 Β· [email protected]https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/ Β· [email protected]https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ Β· [email protected]https://www.openwall.com/lists/oss-security/2023/10/10/6 Β· [email protected]https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack Β· [email protected]https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/ Β· [email protected]http://www.openwall.com/lists/oss-security/2023/10/13/4 Β· af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2023/10/13/9 Β· af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2023/10/18/4 Β· af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2023/10/18/8 Β· af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2023/10/19/6 Β· af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2023/10/20/8 Β· af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2025/08/13/6 Β· af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/security/cve/cve-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/haproxy/haproxy/issues/2312 Β· af854a3a-2127-422b-91ae-364da2661108https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/ Β· af854a3a-2127-422b-91ae-364da2661108https://aws.amazon.com/security/security-bulletins/AWS-2023-011/ Β· af854a3a-2127-422b-91ae-364da2661108https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/ Β· af854a3a-2127-422b-91ae-364da2661108https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/ Β· af854a3a-2127-422b-91ae-364da2661108https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/ Β· af854a3a-2127-422b-91ae-364da2661108https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack Β· af854a3a-2127-422b-91ae-364da2661108https://blog.vespa.ai/cve-2023-44487/ Β· af854a3a-2127-422b-91ae-364da2661108https://bugzilla.proxmox.com/show_bug.cgi?id=4988 Β· af854a3a-2127-422b-91ae-364da2661108https://bugzilla.redhat.com/show_bug.cgi?id=2242803 Β· af854a3a-2127-422b-91ae-364da2661108https://bugzilla.suse.com/show_bug.cgi?id=1216123 Β· af854a3a-2127-422b-91ae-364da2661108https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9 Β· af854a3a-2127-422b-91ae-364da2661108https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/ Β· af854a3a-2127-422b-91ae-364da2661108https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack Β· af854a3a-2127-422b-91ae-364da2661108https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125 Β· af854a3a-2127-422b-91ae-364da2661108https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715 Β· af854a3a-2127-422b-91ae-364da2661108https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve Β· af854a3a-2127-422b-91ae-364da2661108https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764 Β· af854a3a-2127-422b-91ae-364da2661108https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/Azure/AKS/issues/3947 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/Kong/kong/discussions/11741 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/advisories/GHSA-qppj-fm5r-hxr3 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/advisories/GHSA-vx74-f528-fxqg Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/advisories/GHSA-xpw8-rcwv-8f8p Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/akka/akka-http/issues/4323 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/alibaba/tengine/issues/1872 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/apache/apisix/issues/10320 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/apache/httpd-site/pull/10 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/apache/trafficserver/pull/10564 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/bcdannyboy/CVE-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/caddyserver/caddy/issues/5877 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/caddyserver/caddy/releases/tag/v2.7.5 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/dotnet/announcements/issues/277 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/eclipse/jetty.project/issues/10679 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/envoyproxy/envoy/pull/30055 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/etcd-io/etcd/issues/16740 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/facebook/proxygen/pull/466 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/golang/go/issues/63417 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/grpc/grpc-go/pull/6703 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/h2o/h2o/pull/3291 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/junkurihara/rust-rpxy/issues/97 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/kazu-yamamoto/http2/issues/93 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/kubernetes/kubernetes/pull/121120 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/line/armeria/pull/5232 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/micrictor/http2-rst-stream Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/microsoft/CBL-Mariner/pull/6381 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/nghttp2/nghttp2/pull/1961 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/ninenines/cowboy/issues/1615 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/nodejs/node/pull/50121 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/openresty/openresty/issues/930 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/opensearch-project/data-prepper/issues/3474 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/oqtane/oqtane.framework/discussions/3367 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/projectcontour/contour/pull/5826 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/tempesta-tech/tempesta/issues/1986 Β· af854a3a-2127-422b-91ae-364da2661108https://github.com/varnishcache/varnish-cache/issues/3996 Β· af854a3a-2127-422b-91ae-364da2661108https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo Β· af854a3a-2127-422b-91ae-364da2661108https://istio.io/latest/news/security/istio-security-2023-004/ Β· af854a3a-2127-422b-91ae-364da2661108https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/ Β· af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2023/dsa-5549 Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/ Β· af854a3a-2127-422b-91ae-364da2661108https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html Β· af854a3a-2127-422b-91ae-364da2661108https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html Β· af854a3a-2127-422b-91ae-364da2661108https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html Β· af854a3a-2127-422b-91ae-364da2661108https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/ Β· af854a3a-2127-422b-91ae-364da2661108https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://my.f5.com/manage/s/article/K000137106 Β· af854a3a-2127-422b-91ae-364da2661108https://netty.io/news/2023/10/10/4-1-100-Final.html Β· af854a3a-2127-422b-91ae-364da2661108https://news.ycombinator.com/item?id=37830987 Β· af854a3a-2127-422b-91ae-364da2661108https://news.ycombinator.com/item?id=37830998 Β· af854a3a-2127-422b-91ae-364da2661108https://news.ycombinator.com/item?id=37831062 Β· af854a3a-2127-422b-91ae-364da2661108https://news.ycombinator.com/item?id=37837043 Β· af854a3a-2127-422b-91ae-364da2661108https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/ Β· af854a3a-2127-422b-91ae-364da2661108https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected Β· af854a3a-2127-422b-91ae-364da2661108https://security.gentoo.org/glsa/202311-09 Β· af854a3a-2127-422b-91ae-364da2661108https://security.netapp.com/advisory/ntap-20231016-0001/ Β· af854a3a-2127-422b-91ae-364da2661108https://security.netapp.com/advisory/ntap-20240426-0007/ Β· af854a3a-2127-422b-91ae-364da2661108https://security.netapp.com/advisory/ntap-20240621-0006/ Β· af854a3a-2127-422b-91ae-364da2661108https://security.netapp.com/advisory/ntap-20240621-0007/ Β· af854a3a-2127-422b-91ae-364da2661108https://security.paloaltonetworks.com/CVE-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14 Β· af854a3a-2127-422b-91ae-364da2661108https://ubuntu.com/security/CVE-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/ Β· af854a3a-2127-422b-91ae-364da2661108https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event Β· af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2023/dsa-5521 Β· af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2023/dsa-5522 Β· af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2023/dsa-5540 Β· af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2023/dsa-5558 Β· af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2023/dsa-5570 Β· af854a3a-2127-422b-91ae-364da2661108https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 Β· af854a3a-2127-422b-91ae-364da2661108https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/ Β· af854a3a-2127-422b-91ae-364da2661108https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ Β· af854a3a-2127-422b-91ae-364da2661108https://www.openwall.com/lists/oss-security/2023/10/10/6 Β· af854a3a-2127-422b-91ae-364da2661108https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack Β· af854a3a-2127-422b-91ae-364da2661108https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/ Β· af854a3a-2127-422b-91ae-364da2661108https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause Β· af854a3a-2127-422b-91ae-364da2661108https://cert-portal.siemens.com/productcert/html/ssa-082556.html Β· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5ehttps://cert-portal.siemens.com/productcert/html/ssa-341067.html Β· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5ehttps://cert-portal.siemens.com/productcert/html/ssa-784301.html Β· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5ehttps://cert-portal.siemens.com/productcert/html/ssa-832273.html Β· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5ehttps://cert-portal.siemens.com/productcert/html/ssa-915275.html Β· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5ehttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487 Β· 134c704f-9b21-4f2e-91b3-4a467353bcc0
EPSS history
Timeline
  • 10 OCT 00:00Z
    Added to CISA KEV β€” remediate by Oct 31
    kev
  • 10 OCT 00:00Z
    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the…
    cvelistv5