Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Exploits (29)
exploitdb
WORKING POC
by Madhusudhan Rajappa · pythonremotemultiple
https://www.exploit-db.com/exploits/52426
nomisec
WORKING POC
20 stars
by studiogangster · dos
https://github.com/studiogangster/CVE-2023-44487
nomisec
SCANNER
7 stars
by threatlabindonesia · dos
https://github.com/threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC
nomisec
WORKING POC
5 stars
by ndrscodes · dos
https://github.com/ndrscodes/http2-rst-stream-attacker
github
WORKING POC
1 stars
by oscerd · pythonpoc
https://github.com/oscerd/nice-cve-poc/tree/main/CVE-2023-44487
nomisec
WORKING POC
by TLevente20 · poc
https://github.com/TLevente20/HTTP-2-RapidReset-CVE-2023-44487-Testlab
nomisec
SUSPICIOUS
by sastraadiwiguna-purpleeliteteaming · poc
https://github.com/sastraadiwiguna-purpleeliteteaming/DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-
nomisec
WORKING POC
by moften · dos
https://github.com/moften/CVE-2023-44487-HTTP-2-Rapid-Reset-Attack
nomisec
WORKING POC
by madhusudhan-in · dos
https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset
References (168)
... and 148 more
Scores
CVSS v3
7.5
EPSS
0.9440
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Lab Environment
COMMUNITY
Community Lab
+23 more repos
Details
CISA KEV
2023-10-10
VulnCheck KEV
2023-10-10
InTheWild.io
2023-10-10
ENISA EUVD
EUVD-2023-2795
CWE
CWE-400
Status
published
Products (40)
akka/http_server
< 10.5.3
amazon/opensearch_data_prepper
< 2.5.0
apache/apisix
< 3.6.1
apache/solr
< 9.4.0
apache/tomcat
11.0.0 milestone1 (11 CPE variants)
apache/tomcat
8.5.0 - 8.5.93
apache/traffic_server
8.0.0 - 8.1.9
apple/swiftnio_http\/2
< 1.28.0
caddyserver/caddy
< 2.7.5
cisco/business_process_automation
< 3.2.003.009
... and 30 more
Published
Oct 10, 2023
KEV Added
Oct 10, 2023
Tracked Since
Feb 18, 2026