CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-10-10. EPSS: 100% chance of exploitation in the next 30 days.

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Affected products

  • Akka HTTP Server: before 10.5.3 (fixed in 10.5.3)
  • Amazon Opensearch Data Prepper: before 2.5.0 (fixed in 2.5.0)
  • Apache APISIX: before 3.6.1 (fixed in 3.6.1)
  • Apache Solr: before 9.4.0 (fixed in 9.4.0)
  • Apache Tomcat: from 8.5.0, up to and including 8.5.93; from 9.0.0, up to and including 9.0.80; from 10.1.0, up to and including 10.1.13; version 11.0.0 only
  • Apache Traffic Server: from 8.0.0, before 8.1.9 (fixed in 8.1.9); from 9.0.0, before 9.2.3 (fixed in 9.2.3)
  • Apple Swiftnio http/2: before 1.28.0 (fixed in 1.28.0)
  • Caddyserver Caddy: before 2.7.5 (fixed in 2.7.5)
  • Cisco Business Process Automation: before 3.2.003.009 (fixed in 3.2.003.009)
  • Cisco Connected Mobile Experiences: before 11.1 (fixed in 11.1)
  • Cisco Crosswork Data Gateway: before 4.1.3 (fixed in 4.1.3); from 5.0.0, before 5.0.2 (fixed in 5.0.2)
  • Cisco Crosswork Situation Manager: affected versions not specified
  • Cisco Crosswork Zero Touch Provisioning: before 6.0.0 (fixed in 6.0.0)
  • Cisco Data Center Network Manager: affected versions not specified
  • Cisco Enterprise Chat And Email: affected versions not specified
  • Cisco Expressway: before x14.3.3 (fixed in x14.3.3)
  • Cisco Fog Director: before 1.22 (fixed in 1.22)
  • Cisco IOS XE: before 17.15.1 (fixed in 17.15.1)
  • Cisco IOS XR: before 7.11.2 (fixed in 7.11.2)
  • Cisco IoT Field Network Director: before 4.11.0 (fixed in 4.11.0)
  • Cisco NX-OS: before 10.2\(7\) (fixed in 10.2\(7\)); from 10.3\(1\), before 10.3\(5\) (fixed in 10.3\(5\)); from 10.4\(1\), before 10.4\(2\) (fixed in 10.4\(2\))
  • Cisco Prime Access Registrar: before 9.3.3 (fixed in 9.3.3)
  • Cisco Prime Cable Provisioning: before 7.2.1 (fixed in 7.2.1)
  • Cisco Prime Infrastructure: before 3.10.4 (fixed in 3.10.4)
  • Cisco Prime Network Registrar: before 11.2 (fixed in 11.2)
  • and 140 more

Published 2023-10-10. Last modified 2026-08-11.