CVEFinder.io

CVE-2023-44487

⚠️ high
🔍 Scan for this CVE
Summary

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS Score
7.5
High
EPSS Score
94.4
Exploit Probability
Published Date
2023-10-10
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.5% of all 340,620 vulnerabilities in our database.

#107,155
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jul 23, 2024
🔍 Exploitation Status
Active
Exploits detected in the wild
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-11-07
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

📦 Affected Products 276

🔗 References 168

https://arstechnica.com/security/2023/10/how-ddosers...
Press/Media Coverage Third Party Advisory
https://blog.cloudflare.com/technical-breakdown-http...
Technical Description Vendor Advisory
https://blog.qualys.com/vulnerabilities-threat-resea...
Press/Media Coverage Third Party Advisory
https://bugzilla.proxmox.com/show_bug.cgi?id=4988
Issue Tracking Third Party Advisory
https://cloud.google.com/blog/products/identity-secu...
Technical Description Vendor Advisory
https://cloud.google.com/blog/products/identity-secu...
Technical Description Vendor Advisory
https://github.com/dotnet/announcements/issues/277
Issue Tracking Mitigation Vendor Advisory
https://groups.google.com/g/golang-announce/c/iNNxDT...
Mailing List Release Notes Vendor Advisory
https://mailman.nginx.org/pipermail/nginx-devel/2023...
Mailing List Patch Third Party Advisory
https://news.ycombinator.com/item?id=37830998
Issue Tracking Press/Media Coverage
https://www.cisa.gov/news-events/alerts/2023/10/10/h...
Third Party Advisory US Government Resource
https://www.darkreading.com/cloud/internet-wide-zero...
Press/Media Coverage Third Party Advisory
https://www.debian.org/security/2023/dsa-5540
Mailing List Third Party Advisory
https://www.debian.org/security/2023/dsa-5549
Mailing List Third Party Advisory
https://www.debian.org/security/2023/dsa-5558
Mailing List Third Party Advisory
https://www.theregister.com/2023/10/10/http2_rapid_r...
Press/Media Coverage Third Party Advisory

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-58175 ⚠️ high 7.5 0.4 Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0... 2026-07-29
CVE-2026-58177 ⚠️ high 8.1 0.3 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is... 2026-07-29
CVE-2026-58178 ⚠️ high 7.5 0.4 The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects A... 2026-07-29
CVE-2026-58179 ⚠️ high 8.1 0.4 The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affec... 2026-07-29
CVE-2026-58180 ⚠️ high 7.5 0.4 The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache ... 2026-07-29
CVE-2026-58181 ⚠️ high 7.5 0.4 The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue ... 2026-07-29
These CVEs affect the same products