CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-10-10. EPSS: 100% chance of exploitation in the next 30 days.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Affected products
- Akka HTTP Server: before 10.5.3 (fixed in 10.5.3)
- Amazon Opensearch Data Prepper: before 2.5.0 (fixed in 2.5.0)
- Apache APISIX: before 3.6.1 (fixed in 3.6.1)
- Apache Solr: before 9.4.0 (fixed in 9.4.0)
- Apache Tomcat: from 8.5.0, up to and including 8.5.93; from 9.0.0, up to and including 9.0.80; from 10.1.0, up to and including 10.1.13; version 11.0.0 only
- Apache Traffic Server: from 8.0.0, before 8.1.9 (fixed in 8.1.9); from 9.0.0, before 9.2.3 (fixed in 9.2.3)
- Apple Swiftnio http/2: before 1.28.0 (fixed in 1.28.0)
- Caddyserver Caddy: before 2.7.5 (fixed in 2.7.5)
- Cisco Business Process Automation: before 3.2.003.009 (fixed in 3.2.003.009)
- Cisco Connected Mobile Experiences: before 11.1 (fixed in 11.1)
- Cisco Crosswork Data Gateway: before 4.1.3 (fixed in 4.1.3); from 5.0.0, before 5.0.2 (fixed in 5.0.2)
- Cisco Crosswork Situation Manager: affected versions not specified
- Cisco Crosswork Zero Touch Provisioning: before 6.0.0 (fixed in 6.0.0)
- Cisco Data Center Network Manager: affected versions not specified
- Cisco Enterprise Chat And Email: affected versions not specified
- Cisco Expressway: before x14.3.3 (fixed in x14.3.3)
- Cisco Fog Director: before 1.22 (fixed in 1.22)
- Cisco IOS XE: before 17.15.1 (fixed in 17.15.1)
- Cisco IOS XR: before 7.11.2 (fixed in 7.11.2)
- Cisco IoT Field Network Director: before 4.11.0 (fixed in 4.11.0)
- Cisco NX-OS: before 10.2\(7\) (fixed in 10.2\(7\)); from 10.3\(1\), before 10.3\(5\) (fixed in 10.3\(5\)); from 10.4\(1\), before 10.4\(2\) (fixed in 10.4\(2\))
- Cisco Prime Access Registrar: before 9.3.3 (fixed in 9.3.3)
- Cisco Prime Cable Provisioning: before 7.2.1 (fixed in 7.2.1)
- Cisco Prime Infrastructure: before 3.10.4 (fixed in 3.10.4)
- Cisco Prime Network Registrar: before 11.2 (fixed in 11.2)
- and 140 more
Published 2023-10-10. Last modified 2026-08-11.