---
cve: "CVE-2023-44487"
severity: "HIGH"
cvss: 7.5
epss: "100%"
vendor: "n/a"
kev: true
exploited: true
published: "2023-10-10 14:15:10"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T14:59:22+02:00"
---

# CVE-2023-44487

> 7.5 HIGH · ⚠️ CISA KEV (1071 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-52426 — HTTP/2 2.0 - Denial Of Service (DOS)](https://www.exploit-db.com/exploits/52426)

## Patch verfügbar (OSV)

- 1a3b131141fed9468d9da1167c7fcb37902935ed (Commit)
- a7081f551473ba57ace1d5e10c8cf486c1e715a1 (Commit)

## Referenzen

- <https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73>
- <https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/>
- <https://aws.amazon.com/security/security-bulletins/AWS-2023-011/>
- <https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack>
- <https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/>
- <https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/>
- <https://news.ycombinator.com/item?id=37831062>
- <https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/>
- <https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack>
- <https://github.com/envoyproxy/envoy/pull/30055>
- <https://github.com/haproxy/haproxy/issues/2312>
- <https://github.com/eclipse/jetty.project/issues/10679>
- <https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764>
- <https://github.com/nghttp2/nghttp2/pull/1961>
- <https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-44487) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
