The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Loading...
Loading...
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-10-10), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.5 retained for reference. Confidence: HIGH.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
October 10, 2023
May 12, 2026
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.4 security update
Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.15.0 release
Red Hat Enhancement Advisory: Advisory for publishing Helm 3.13.2 GA release
Red Hat Security Advisory: OpenShift Container Platform 4.15.9 bug fix and security update
Red Hat Enhancement Advisory: Red Hat Developer Hub 1.1 release
Red Hat Security Advisory: Kube Descheduler Operator for Red Hat OpenShift 5.0.0 for RHEL 9:security update
Red Hat Security Advisory: Run Once Duration Override Operator for Red Hat OpenShift 1.1.0 for RHEL 9
Red Hat Security Advisory: OpenShift Container Platform 4.15.0 bug fix and security update
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| com.typesafe.akka:akka-http-core | 3.0.0-RC1 | 10.5.3 | — |
| com.typesafe.akka:akka-http-core_2.11 | 10.0.0 ... 3.0.0-RC1 (58 versions) | — | — |
| com.typesafe.akka:akka-http-core_2.12 | 10.0.0 ... 10.5.2 (59 versions) | 10.5.3 | — |
| com.typesafe.akka:akka-http-core_2.13 | 10.1.10 ... 10.5.2 (31 versions) | 10.5.3 | — |
| org.apache.tomcat.embed:tomcat-embed-core | 8.5.0 ... 8.5.93 (78 versions) | 8.5.94 | — |
| org.apache.tomcat:tomcat-coyote | 8.5.0 ... 8.5.93 (78 versions) | 8.5.94 | — |
| org.eclipse.jetty.http2:http2-common | 11.0.0 ... 11.0.9 (17 versions) | 11.0.17 | — |
| org.eclipse.jetty.http2:http2-server | 11.0.0 ... 11.0.9 (17 versions) | 11.0.17 | — |
| org.eclipse.jetty.http2:jetty-http2-common | 12.0.0, 12.0.1 | 12.0.2 | — |
| org.eclipse.jetty.http2:jetty-http2-server | 12.0.0, 12.0.1 | 12.0.2 | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| golang.org/x/net | — | 0.17.0 | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| github.com/apple/swift-nio-http2 | — | 1.28.0 | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
MITRE: CVE-2023-44487 HTTP/2 Rapid Reset Attack
RHBA-2023:5806 — Important
RHBA-2023:5949 — Important
RHBA-2023:6078 — Important
RHBA-2023:6109 — Important
RHBA-2023:6254 — Important
RHBA-2023:6863 — Important
RHBA-2023:7492 — Important
RHBA-2024:0815 — Important
RHEA-2023:6562 — Important
RHEA-2023:6741 — Important
RHEA-2023:7235 — Important
RHEA-2023:7239 — Important
RHEA-2023:7327 — Important
RHEA-2024:0555 — Important
RHSA-2023:5006 — Important
RHSA-2023:5009 — Important
RHSA-2023:5530 — Important
RHSA-2023:5541 — Important
RHSA-2023:5542 — Important
RHSA-2023:5679 — Important
RHSA-2023:5705 — Important
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
poc for the rst dos attack discovered in 2023
Open source ↗HTTP/2 2.0 - Denial Of Service (DOS)
Open source ↗Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept
Open source ↗Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the server's responses.
Open source ↗A python based exploit to test out rapid reset attack (CVE-2023-44487)
Open source ↗Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)
Open source ↗Proof of concept for DoS exploit
Open source ↗Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-44487
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
msrc · redhat
CWE-400