CVE-2023-44487
HTTP/2 Rapid Reset Attack Vulnerability
Description
CVE-2023-44487 is a denial of service vulnerability in the HTTP/2 protocol, widely known as the "HTTP/2 Rapid Reset" attack. This flaw allows a remote attacker to consume excessive server resources by rapidly opening and canceling HTTP/2 streams using RST_STREAM frames, overwhelming the target server without requiring authentication or user interaction. The vulnerability affects virtually every web server, proxy, and load balancer that implements HTTP/2, including products from IETF, nghttp2, Netty, Envoy, Caddy, Golang, F5, and many others. CVE-2023-44487 was actively exploited in the wild from August through October 2023 to launch record-breaking distributed denial of service (DDoS) attacks, and CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of October 31, 2023. With an EPSS score of 94.4%, indicating near-certain exploitation, this HTTP/2 vulnerability demands immediate attention from any organization exposing HTTP/2 endpoints.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| siemens | simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware | >= 3.1.5 |
| siemens | sinec ins | < 1.0; 1.0 |
| siemens | sinec nms | < 3.0 |
| siemens | st7 scadaconnect | < 1.1 |
| siemens | ruggedcom ape1808 firmware | - |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware | >= 3.1.5 |
| siemens | siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware | >= 3.1.5 |
| ietf | http | 2.0 |
| nghttp2 | nghttp2 | < 1.57.0 |
| netty | netty | < 4.1.100 |
| envoyproxy | envoy | 1.24.10; 1.25.9; 1.26.4; 1.27.0 |
| eclipse | jetty | < 9.4.53; >= 10.0.0, < 10.0.17; >= 11.0.0, < 11.0.17; >= 12.0.0, < 12.0.2 |
| caddyserver | caddy | < 2.7.5 |
| golang | go | < 1.20.10; >= 1.21.0, < 1.21.3 |
| golang | http2 | < 0.17.0 |
| golang | networking | < 0.17.0 |
| f5 | big-ip access policy manager | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
| f5 | big-ip advanced firewall manager | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
| f5 | big-ip advanced web application firewall | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
| f5 | big-ip analytics | >= 13.1.0, <= 13.1.5; >= 14.1.0, <= 14.1.5; >= 15.1.0, <= 15.1.10; >= 16.1.0, <= 16.1.4; 17.1.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
- http://www.openwall.com/lists/oss-security/2023/10/10/6(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/10/7(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/13/4(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/13/9(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/18/4(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/18/8(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/19/6(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2023/10/20/8(Mailing List, Third Party Advisory)
- https://access.redhat.com/security/cve/cve-2023-44487(Vendor Advisory)
- https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/(Press/Media Coverage, Third Party Advisory)
- https://aws.amazon.com/security/security-bulletins/AWS-2023-011/(Third Party Advisory)
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/(Technical Description, Vendor Advisory)
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/(Third Party Advisory, Vendor Advisory)
- https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/(Vendor Advisory)
- https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack(Press/Media Coverage, Third Party Advisory)
- https://blog.vespa.ai/cve-2023-44487/(Vendor Advisory)
- https://bugzilla.proxmox.com/show_bug.cgi?id=4988(Issue Tracking, Third Party Advisory)
- https://bugzilla.redhat.com/show_bug.cgi?id=2242803(Issue Tracking, Vendor Advisory)
- https://bugzilla.suse.com/show_bug.cgi?id=1216123(Issue Tracking, Vendor Advisory)
- https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9(Mailing List, Patch, Vendor Advisory)
- https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/(Technical Description, Vendor Advisory)
- https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack(Technical Description, Vendor Advisory)
- https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125(Vendor Advisory)
- https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715(Third Party Advisory)
- https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve(Broken Link)
- https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764(Vendor Advisory)
- https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088(Issue Tracking, Patch)
- https://github.com/Azure/AKS/issues/3947(Issue Tracking)
- https://github.com/Kong/kong/discussions/11741(Issue Tracking)
- https://github.com/advisories/GHSA-qppj-fm5r-hxr3(Vendor Advisory)
- https://github.com/advisories/GHSA-vx74-f528-fxqg(Mitigation, Patch, Vendor Advisory)
- https://github.com/advisories/GHSA-xpw8-rcwv-8f8p(Patch, Vendor Advisory)
- https://github.com/akka/akka-http/issues/4323(Issue Tracking)
- https://github.com/alibaba/tengine/issues/1872(Issue Tracking)
- https://github.com/apache/apisix/issues/10320(Issue Tracking)
- https://github.com/apache/httpd-site/pull/10(Issue Tracking)
- https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113(Product)
- https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2(Product, Third Party Advisory)
- https://github.com/apache/trafficserver/pull/10564(Issue Tracking, Patch)
- https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487(Vendor Advisory)
- https://github.com/bcdannyboy/CVE-2023-44487(Third Party Advisory)
- https://github.com/caddyserver/caddy/issues/5877(Issue Tracking, Vendor Advisory)
- https://github.com/caddyserver/caddy/releases/tag/v2.7.5(Release Notes, Third Party Advisory)
- https://github.com/dotnet/announcements/issues/277(Issue Tracking, Mitigation, Vendor Advisory)
- https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73(Product, Release Notes)
- https://github.com/eclipse/jetty.project/issues/10679(Issue Tracking)
- https://github.com/envoyproxy/envoy/pull/30055(Issue Tracking, Patch)
- https://github.com/etcd-io/etcd/issues/16740(Issue Tracking, Patch)
- https://github.com/facebook/proxygen/pull/466(Issue Tracking, Patch)
- https://github.com/golang/go/issues/63417(Issue Tracking)
- https://github.com/grpc/grpc-go/pull/6703(Issue Tracking, Patch)
- https://github.com/grpc/grpc/releases/tag/v1.59.2(Mailing List)
- https://github.com/h2o/h2o/pull/3291(Issue Tracking, Patch)
- https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf(Vendor Advisory)
- https://github.com/haproxy/haproxy/issues/2312(Issue Tracking)
- https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244(Product)
- https://github.com/junkurihara/rust-rpxy/issues/97(Issue Tracking)
- https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1(Patch)
- https://github.com/kazu-yamamoto/http2/issues/93(Issue Tracking)
- https://github.com/kubernetes/kubernetes/pull/121120(Issue Tracking, Patch)
- https://github.com/line/armeria/pull/5232(Issue Tracking, Patch)
- https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632(Patch)
- https://github.com/micrictor/http2-rst-stream(Exploit, Third Party Advisory)
- https://github.com/microsoft/CBL-Mariner/pull/6381(Issue Tracking, Patch)
- https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61(Patch)
- https://github.com/nghttp2/nghttp2/pull/1961(Issue Tracking, Patch)
- https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0(Release Notes)
- https://github.com/ninenines/cowboy/issues/1615(Issue Tracking)
- https://github.com/nodejs/node/pull/50121(Issue Tracking)
- https://github.com/openresty/openresty/issues/930(Issue Tracking)
- https://github.com/opensearch-project/data-prepper/issues/3474(Issue Tracking, Patch)
- https://github.com/oqtane/oqtane.framework/discussions/3367(Issue Tracking)
- https://github.com/projectcontour/contour/pull/5826(Issue Tracking, Patch)
- https://github.com/tempesta-tech/tempesta/issues/1986(Issue Tracking)
- https://github.com/varnishcache/varnish-cache/issues/3996(Issue Tracking)
- https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo(Mailing List, Release Notes, Vendor Advisory)
- https://istio.io/latest/news/security/istio-security-2023-004/(Vendor Advisory)
- https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/(Vendor Advisory)
- https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html(Mailing List, Third Party Advisory)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html(Mailing List)
- https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/(Mailing List)
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/(Mailing List)
- https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html(Mailing List, Third Party Advisory)
- https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html(Mailing List, Patch, Third Party Advisory)
- https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html(Third Party Advisory)
- https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/(Patch, Vendor Advisory)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487(Mitigation, Patch, Vendor Advisory)
- https://my.f5.com/manage/s/article/K000137106(Vendor Advisory)
- https://netty.io/news/2023/10/10/4-1-100-Final.html(Release Notes, Vendor Advisory)
- https://news.ycombinator.com/item?id=37830987(Issue Tracking)
- https://news.ycombinator.com/item?id=37830998(Issue Tracking, Press/Media Coverage)
- https://news.ycombinator.com/item?id=37831062(Issue Tracking)
- https://news.ycombinator.com/item?id=37837043(Issue Tracking)
- https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/(Third Party Advisory)
- https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected(Third Party Advisory)
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ(Vendor Advisory)
- https://security.gentoo.org/glsa/202311-09(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20231016-0001/(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20240426-0007/(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20240621-0006/(Exploit, Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20240621-0007/(Third Party Advisory)
- https://security.paloaltonetworks.com/CVE-2023-44487(Vendor Advisory)
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14(Release Notes)
- https://ubuntu.com/security/CVE-2023-44487(Vendor Advisory)
- https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/(Third Party Advisory)
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487(Third Party Advisory, US Government Resource)
- https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event(Press/Media Coverage, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5521(Mailing List, Vendor Advisory)
- https://www.debian.org/security/2023/dsa-5522(Mailing List, Vendor Advisory)
- https://www.debian.org/security/2023/dsa-5540(Mailing List, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5549(Mailing List, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5558(Mailing List, Third Party Advisory)
- https://www.debian.org/security/2023/dsa-5570(Third Party Advisory)
- https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487(Third Party Advisory, Vendor Advisory)
- https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/(Vendor Advisory)
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/(Mitigation, Vendor Advisory)
- https://www.openwall.com/lists/oss-security/2023/10/10/6(Mailing List, Third Party Advisory)
- https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack(Press/Media Coverage)
- https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/(Press/Media Coverage, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2025/08/13/6(Third Party Advisory)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/(Mailing List, Third Party Advisory)
- https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-341067.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-784301.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-832273.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-915275.html(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487(US Government Resource)
Weakness Type
CWE-400: Uncontrolled Resource Consumption
CWE-400 describes a weakness where the software does not properly control the allocation and maintenance of a limited resource, allowing an attacker to influence the amount of resources consumed and ultimately cause a denial of service. In the case of CVE-2023-44487, the HTTP/2 protocol implementation fails to limit how quickly a client can open and reset streams, enabling an attacker to exhaust server-side resources such as memory and CPU by sending a flood of rapid stream reset requests.
Learn more: CWE-400 — Uncontrolled Resource Consumption
Impact Analysis
CVE-2023-44487 carries a CVSS v3.1 score of 7.5 (High severity) and is remotely exploitable without physical access, making any internet-facing HTTP/2 service a potential target. Attack Complexity (Low): The vulnerability requires no special conditions or preparation to exploit. Privileges Required (None): No authentication is needed, meaning any remote attacker can launch the attack. User Interaction (None): No action from a legitimate user is required to trigger the exploit. Availability Impact (High): A successful attack can render the targeted service completely unavailable, disrupting business operations, customer access, and dependent services. While confidentiality and integrity are not directly affected, the denial of service impact is severe — the attack was used to generate DDoS traffic volumes exceeding 398 million requests per second. The EPSS score of 94.4% confirms that active exploitation is near-certain, and organizations running HTTP/2 services face a high likelihood of being targeted.
Exploit Maturity
Public exploit code is available for CVE-2023-44487 via micrictor’s HTTP/2 RST stream tool on GitHub, which provides a proof-of-concept for the rapid reset attack technique. CISA has confirmed active exploitation in the wild, having added CVE-2023-44487 to the Known Exploited Vulnerabilities catalog with a remediation deadline of October 31, 2023. The EPSS score of 94.4% (99.97th percentile) indicates near-certain exploitation activity, reflecting the widespread and ongoing abuse of this vulnerability in massive DDoS campaigns. Major cloud providers including Google Cloud, Cloudflare, and AWS reported mitigating attacks exploiting this flaw at unprecedented scale during August through October 2023.
Remediation
- Apply vendor-specific patches and updates immediately. As the KEV required action states: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Update nghttp2 to version 1.57.0 or later, Netty to 4.1.100.Final or later, Caddy to 2.7.5 or later, and apply relevant patches for Golang, Envoy, Jetty, Apache Tomcat, Nginx, HAProxy, F5 BIG-IP, and all other affected HTTP/2 implementations in your environment.
- Configure HTTP/2 stream limits and rate controls. Implement server-side limits on the number of concurrent streams and the rate of RST_STREAM frames accepted per connection. Many web servers and reverse proxies have introduced configuration options specifically to mitigate rapid reset attacks.
- Deploy DDoS mitigation at the network edge. Use a web application firewall (WAF) or DDoS protection service (such as Cloudflare, AWS Shield, or similar) to detect and filter HTTP/2 rapid reset patterns before they reach origin servers.
- Monitor server resource consumption and connection behavior. Review HTTP/2 connection logs for anomalous patterns such as high volumes of stream creation followed by immediate RST_STREAM frames. Set up alerts for unusual spikes in CPU, memory, or connection counts.
- Implement resource consumption controls as a long-term hardening measure. Enforce per-connection and per-client resource limits, implement connection-level rate limiting, and consider disabling HTTP/2 on endpoints where it is not needed to reduce the attack surface.
Technical Details
CVE-2023-44487 exploits a fundamental aspect of the HTTP/2 protocol’s stream multiplexing mechanism. In HTTP/2, a client can open multiple streams on a single TCP connection and cancel any of them by sending a RST_STREAM frame. The rapid reset attack works by sending a request to open a stream and immediately following it with a RST_STREAM to cancel that request, then repeating this pattern at high speed. Attack Vector (Network): The attack is conducted entirely over the network, requiring only a TCP connection to the target’s HTTP/2 endpoint. Attack Complexity (Low): No special conditions are needed — the attacker simply sends well-formed HTTP/2 frames in rapid succession. The server processes each stream open request, allocating resources, but the immediate cancellation prevents the server from efficiently cleaning up those resources. Because the client cancels each request, the server’s response data is never sent back, reducing bandwidth costs for the attacker while maximizing server-side resource consumption. This asymmetry between client cost and server cost is what makes the attack so effective, enabling single machines to generate hundreds of millions of requests per second against vulnerable endpoints.
Frequently Asked Questions
Is CVE-2023-44487 being actively exploited?
Yes, CVE-2023-44487 has been actively exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of October 31, 2023. The vulnerability was used in record-breaking DDoS attacks from August through October 2023, with Google Cloud reporting mitigation of an attack peaking above 398 million requests per second.
What products are affected by CVE-2023-44487?
CVE-2023-44487 affects virtually every product that implements the HTTP/2 protocol. This includes web servers (Nginx, Apache, Caddy, LiteSpeed), proxies and load balancers (Envoy, HAProxy, Traefik), programming language libraries (Golang net/http2, nghttp2, Netty, Jetty), application platforms (Apache Tomcat, Node.js, .NET), and network appliances such as F5 BIG-IP product lines. Cloud-hosted services may also be affected depending on their HTTP/2 implementation.
How do I fix CVE-2023-44487?
Apply the latest security patches from your HTTP/2 implementation vendor. Key updates include nghttp2 1.57.0+, Netty 4.1.100.Final+, and Caddy 2.7.5+. Additionally, configure HTTP/2 stream concurrency limits and RST_STREAM rate controls on your servers, and deploy DDoS mitigation at the network edge. See the Remediation section above for detailed steps.
How severe is CVE-2023-44487?
CVE-2023-44487 is rated High severity with a CVSS v3.1 score of 7.5. While it only affects availability (not confidentiality or integrity), the real-world impact has been extreme — it enabled the largest DDoS attacks ever recorded. The EPSS score of 94.4% (99.97th percentile) indicates near-certain exploitation, making immediate patching essential for any organization with HTTP/2 endpoints.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.