CVE-2023-44487

Aliases:CGA-5jp5-95p2-jw83BIT-apisix-2023-44487BIT-aspnet-core-2023-44487BIT-contour-2023-44487BIT-dotnet-2023-44487BIT-dotnet-sdk-2023-44487BIT-envoy-2023-44487BIT-golang-2023-44487BIT-jenkins-2023-44487BIT-kong-2023-44487BIT-nginx-2023-44487BIT-nginx-gateway-2023-44487BIT-nginx-ingress-controller-2023-44487BIT-node-2023-44487BIT-node-min-2023-44487BIT-solr-2023-44487BIT-tomcat-2023-44487BIT-varnish-2023-44487CGA-4mmr-qwxr-f88gCGA-5v4r-558c-254rCGA-9w4r-68hh-64j5CGA-m49h-wjp5-j434CGA-mp43-q6p3-96v2GHSA-m425-mq94-257gGHSA-qppj-fm5r-hxr3GO-2023-2153GHSA-M425-MQ94-257G
Advisory lineage Upstream: 0 Downstream: 170
Analyzed
Published: 10 Oct 2023, 00:00
Last modified:12 May 2026, 10:52

Vulnerability Summary

Overall Risk (default)
high
59/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
94.4% CRITICAL
94% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

10 Oct 2023, 00:00
Published
Vulnerability first disclosed
10 Oct 2023, 00:00
Added to CISA KEV
HTTP/2 Rapid Reset Attack Vulnerability
31 Oct 2023, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
12 May 2026, 10:52
Last Modified
Vulnerability information updated

Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS Metrics

  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H

EPSS Trends

Current EPSS score: 94.40% Percentile: 100%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • akkahttp_server

    < 10.5.3

  • amazonopensearch_data_prepper

    < 2.5.0

  • UnknownAPISIX

    < 3.6.1

  • UnknownSolr

    < 9.4.0

  • UnknownTomcat

    ≥ 8.5.0, ≤ 8.5.93 | ≥ 9.0.0, ≤ 9.0.80 | ≥ 10.1.0, ≤ 10.1.13 | 11.0.0:milestone1 | 11.0.0:milestone10 | 11.0.0:milestone11 | 11.0.0:milestone2 | 11.0.0:milestone3 | 11.0.0:milestone4 | 11.0.0:milestone5 | 11.0.0:milestone6 | 11.0.0:milestone7 | 11.0.0:milestone8 | 11.0.0:milestone9

  • apachetraffic_server

    ≥ 8.0.0, < 8.1.9 | ≥ 9.0.0, < 9.2.3

  • chainguardcluster-autoscaler-1.26

    < 1.26.4-r4

  • chainguardcluster-autoscaler-1.26-compat

    < 1.26.4-r4

  • chainguardcluster-autoscaler-1.27

    < 1.27.3-r6

  • chainguardcluster-autoscaler-1.27-compat

    < 1.27.3-r6

  • chainguardcluster-autoscaler-1.28

    < 1.28.0-r6

  • chainguardcluster-autoscaler-1.28-compat

    < 1.28.0-r6

  • chainguardk3d

    < 5.6.0-r6

  • chainguardkeda-2.8

    < 2.8.2-r3

  • chainguardkeda-2.9

    < 2.9.1-r5

  • wolficluster-autoscaler-1.26

    < 1.26.4-r4

  • wolficluster-autoscaler-1.26-compat

    < 1.26.4-r4

  • wolficluster-autoscaler-1.27

    < 1.27.3-r6

  • wolficluster-autoscaler-1.27-compat

    < 1.27.3-r6

  • wolficluster-autoscaler-1.28

    < 1.28.0-r6

  • wolficluster-autoscaler-1.28-compat

    < 1.28.0-r6

  • appleswiftnio_http\/2

    < 1.28.0

  • caddyservercaddy

    < 2.7.5

  • ciscobusiness_process_automation

    < 3.2.003.009

  • ciscoconnected_mobile_experiences

    < 11.1

  • ciscocrosswork_data_gateway

    < 4.1.3 | ≥ 5.0.0, < 5.0.2

  • ciscocrosswork_situation_manager

    na

  • ciscocrosswork_zero_touch_provisioning

    < 6.0.0

  • ciscodata_center_network_manager

    na

  • ciscoenterprise_chat_and_email

    na

  • ciscoexpressway

    < x14.3.3

  • ciscofirepower_threat_defense

    < 7.4.2

  • ciscofog_director

    < 1.22

  • ciscoios_xe

    < 17.15.1

  • UnknownIOS XR

    < 7.11.2

  • ciscoiot_field_network_director

    < 4.11.0

  • UnknownNX-OS

    < 10.2\(7\) | ≥ 10.3\(1\), < 10.3\(5\) | ≥ 10.4\(1\), < 10.4\(2\)

  • ciscoprime_access_registrar

    < 9.3.3

  • ciscoprime_cable_provisioning

    < 7.2.1

  • ciscoprime_infrastructure

    < 3.10.4

  • ciscoprime_network_registrar

    < 11.2

  • ciscosecure_dynamic_attributes_connector

    < 2.2.0

  • ciscosecure_malware_analytics

    < 2.19.2

  • ciscosecure_web_appliance_firmware

    < 15.1.0

  • ciscotelepresence_video_communication_server

    < x14.3.3

  • ciscoultra_cloud_core_-_policy_control_function

    < 2024.01.0 | 2024.01.0

  • ciscoultra_cloud_core_-_serving_gateway_function

    < 2024.02.0

  • ciscoultra_cloud_core_-_session_management_function

    < 2024.02.0

  • ciscounified_attendant_console_advanced

    na

  • ciscounified_contact_center_domain_manager

    na

Showing first 50 affected entries in server-rendered view.

References (255)