CVE-2023-44487

HIGH KEV LAB

Ietf HTTP < 1.57.0 - Denial of Service

Title source: rule

Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Exploits (29)

exploitdb WORKING POC
by Madhusudhan Rajappa · pythonremotemultiple
https://www.exploit-db.com/exploits/52426
nomisec SCANNER 241 stars
by bcdannyboy · dos
https://github.com/bcdannyboy/CVE-2023-44487
nomisec WORKING POC 71 stars
by secengjeff · dos
https://github.com/secengjeff/rapidresetclient
nomisec WORKING POC 53 stars
by Appsynergy-io · poc
https://github.com/Appsynergy-io/CVE-2023-44487
nomisec WORKING POC 20 stars
by studiogangster · dos
https://github.com/studiogangster/CVE-2023-44487
nomisec WORKING POC 13 stars
by nxenon · dos
https://github.com/nxenon/cve-2023-44487
nomisec SCANNER 7 stars
by threatlabindonesia · dos
https://github.com/threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC
nomisec WORKING POC 5 stars
by ndrscodes · dos
https://github.com/ndrscodes/http2-rst-stream-attacker
nomisec WORKING POC 2 stars
by tpirate · dos
https://github.com/tpirate/cve-2023-44487-POC
nomisec WORKING POC 2 stars
by ReToCode · dos
https://github.com/ReToCode/golang-CVE-2023-44487
nomisec WORKING POC 1 stars
by zanks08 · dos
https://github.com/zanks08/cve-2023-44487-demo
github WORKING POC 1 stars
by oscerd · pythonpoc
https://github.com/oscerd/nice-cve-poc/tree/main/CVE-2023-44487
nomisec WORKING POC
by galletitaconpate · dos
https://github.com/galletitaconpate/CVE-2023-44487
nomisec WORKING POC
by TLevente20 · poc
https://github.com/TLevente20/HTTP-2-RapidReset-CVE-2023-44487-Testlab
nomisec WORKING POC
by dryfryce · poc
https://github.com/dryfryce/phoenix-http2
nomisec WORKING POC
by dryfryce · poc
https://github.com/dryfryce/phoenix-h2
nomisec WORKING POC
by ReGeLePuMa · dos
https://github.com/ReGeLePuMa/HTTP-2-Rapid-Reset-DDos
nomisec SUSPICIOUS
by sastraadiwiguna-purpleeliteteaming · poc
https://github.com/sastraadiwiguna-purpleeliteteaming/DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-
nomisec WORKING POC
by moften · dos
https://github.com/moften/CVE-2023-44487-HTTP-2-Rapid-Reset-Attack
nomisec WORKING POC
by madhusudhan-in · dos
https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset
nomisec WORKING POC
by BMG-Black-Magic · dos
https://github.com/BMG-Black-Magic/CVE-2023-44487
nomisec WORKING POC
by aulauniversal · dos
https://github.com/aulauniversal/CVE-2023-44487
nomisec STUB
by TYuan0816 · poc
https://github.com/TYuan0816/cve-2023-44487
nomisec WORKING POC
by sigridou · dos
https://github.com/sigridou/CVE-2023-44487-
nomisec WORKING POC
by pabloec20 · dos
https://github.com/pabloec20/rapidreset
nomisec SCANNER
by ByteHackr · dos
https://github.com/ByteHackr/CVE-2023-44487
vulncheck_xdb WORKING POC
dos
https://github.com/Syn2Much/l7-slayer
vulncheck_xdb WORKING POC
dos
https://github.com/imabee101/CVE-2023-44487

References (168)

... and 148 more

Scores

CVSS v3 7.5
EPSS 0.9440
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull nginx:1.23
docker pull nginx:1.25.2
+23 more repos

Details

CISA KEV 2023-10-10
VulnCheck KEV 2023-10-10
InTheWild.io 2023-10-10
ENISA EUVD EUVD-2023-2795
CWE
CWE-400
Status published
Products (40)
akka/http_server < 10.5.3
amazon/opensearch_data_prepper < 2.5.0
apache/apisix < 3.6.1
apache/solr < 9.4.0
apache/tomcat 11.0.0 milestone1 (11 CPE variants)
apache/tomcat 8.5.0 - 8.5.93
apache/traffic_server 8.0.0 - 8.1.9
apple/swiftnio_http\/2 < 1.28.0
caddyserver/caddy < 2.7.5
cisco/business_process_automation < 3.2.003.009
... and 30 more
Published Oct 10, 2023
KEV Added Oct 10, 2023
Tracked Since Feb 18, 2026