CVE-2023-44487

Updated: 2025-08-20 03:00:56.313216

Description:

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.5

Known exploits

Added Date Description Due Date Notes
2023-10-10 HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). 2023-10-31 This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS Stream 8 ELS nginx 1.14.1 7.5 HIGH Ignored 2024-07-01 14:25:37 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
CentOS 7 ELS nginx 1.20.1 7.5 HIGH Released CLSA-2024:1715280815 2024-05-29 10:11:38 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
Ubuntu 18.04 ELS nginx 1.14.0-0 7.5 HIGH Released CLSA-2023:1697742355 2023-10-19 21:07:58 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
CentOS 6 ELS nginx 1.10.3 7.5 HIGH Released CLSA-2023:1698101447 2023-11-06 04:09:29 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
AlmaLinux 9.2 ESU nginx 1.20.1 7.5 HIGH Already Fixed 2025-03-20 03:51:24
Ubuntu 16.04 ELS nginx 1.10.3-0 7.5 HIGH Released CLSA-2023:1697742241 2023-10-19 21:07:52 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
AlmaLinux 9.2 ESU nodejs 16.20.2 7.5 HIGH Already Fixed 2025-07-30 01:49:02
AlmaLinux 9.2 ESU tomcat 9.0.62 7.5 HIGH Already Fixed 2025-01-17 01:23:37
CentOS 7 ELS tomcat 7.0.76 7.5 HIGH Not Vulnerable 2024-04-11 10:04:00 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
CentOS 6 ELS tomcat6 6.0.24 7.5 HIGH Ignored 2023-10-19 09:29:03 nginx developers disagree with the vulnerability status. The problem with HTTP/2 is inherent and it'...
Total: 57