GHSA-qppj-fm5r-hxr3 · Severity: medium · Ecosystem: go — HTTP/2 Stream Cancellation Attack
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Conclusion & alert: CVE-2023-44487 is rated Critical Active Threat (89.9/100): CVSS High severity, with high exploitation likelihood (EPSS 94.45%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2023-10-10) affecting IETF / HTTP/2. a weakness (CWE-400) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: HTTP/2 Rapid Reset Attack Vulnerability · CISA KEV detail
: 2023-10-10
: 2023-10-31
: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 52426 | exploit_db | edb | 2025-09-16 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-28 | 94.49% | 94.45% | -0.05% |
| 2 | 2026-05-22 | 94.45% | 94.49% | +0.05% |
| 3 | 2026-05-07 | — | 94.45% | — |
Full EPSS history (67 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-qppj-fm5r-hxr3 · Severity: medium · Ecosystem: go — HTTP/2 Stream Cancellation Attack
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2023-44487: 15 source package rows (dotnet6-build, dotnet6-runtime, …); 84 state rows across 13 repos (3.17-main, 3.18-community, 3.18-main, 3.19-community, 3.19-main, 3.20-community, 3.20-main, 3.21-community, 3.21-main, 3.22-community, 3.22-main, edge-community, edge-main); fixed 84, open 0. | https://security.alpinelinux.org/vuln/CVE-2023-44487 |
debian
|
end-of-life | CVE-2023-44487 end-of-life priority: Debian including 12 source packages (dnsdist, grpc, …), 54 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 41, open 13. | https://security-tracker.debian.org/tracker/CVE-2023-44487 |
gentoo
|
high | CVE-2023-44487: 4 GLSA(s) (202311-09, 202408-10, 202412-14, 202505-11), 4 atom(s) (app-admin/consul, dev-lang/go, net-libs/nghttp2, net-libs/nodejs); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-44487 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2023-44487 |
suse
|
high | CVE-2023-44487 severity important: SUSE including 924 source package names (1.1.0-1.1:nginx-1.21.5-150600.10.3.1, 1.2.3-2.2.63:libnghttp2-14-1.40.0-150200.12.1, …), 2378 product×package rows across 326 product lines (Container bci/bci-init, Container bci/golang, … (326 product lines)): Fixed 1987, Known Not Affected 207, Known Affected 180, First Fixed 4. | https://www.suse.com/security/cve/CVE-2023-44487/ |
ubuntu
|
high | CVE-2023-44487 high priority: Ubuntu including 14 source packages (dnsdist, dotnet6, …), 165 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 63, released 46, DNE 35, ignored 21. | https://ubuntu.com/security/CVE-2023-44487 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| siemens | simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware | >= 3.1.5 | cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:* |
| siemens | sinec_ins | < 1.0 | cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:* |
| siemens | sinec_ins | 1.0 | cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:* |
| siemens | sinec_ins | 1.0 | cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:* |
| siemens | sinec_ins | 1.0 | cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:* |
| siemens | sinec_ins | 1.0 | cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_1:*:*:*:*:*:* |
| siemens | sinec_ins | 1.0 | cpe:2.3:a:siemens:sinec_ins:1.0:sp2_update_2:*:*:*:*:*:* |
| siemens | sinec_nms | < 3.0 | cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:* |
| siemens | st7_scadaconnect | < 1.1 | cpe:2.3:a:siemens:st7_scadaconnect:*:*:*:*:*:*:*:* |
| siemens | ruggedcom_ape1808_firmware | — | cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:* |
| siemens | simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware | >= 3.1.5 | cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:* |
| siemens | siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware | >= 3.1.5 | cpe:2.3:o:siemens:siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:* |
| ietf | http | 2.0 | cpe:2.3:a:ietf:http:2.0:*:*:*:*:*:*:* |
| nghttp2 | nghttp2 | < 1.57.0 | cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:* |
| netty | netty | < 4.1.100 | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* |
| envoyproxy | envoy | 1.24.10 | cpe:2.3:a:envoyproxy:envoy:1.24.10:*:*:*:*:*:*:* |
| envoyproxy | envoy | 1.25.9 | cpe:2.3:a:envoyproxy:envoy:1.25.9:*:*:*:*:*:*:* |
| envoyproxy | envoy | 1.26.4 | cpe:2.3:a:envoyproxy:envoy:1.26.4:*:*:*:*:*:*:* |
| envoyproxy | envoy | 1.27.0 | cpe:2.3:a:envoyproxy:envoy:1.27.0:*:*:*:*:*:*:* |
| eclipse | jetty | < 9.4.53 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 10.0.0, < 10.0.17 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 11.0.0, < 11.0.17 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 12.0.0, < 12.0.2 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| caddyserver | caddy | < 2.7.5 | cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:* |
| golang | go | < 1.20.10 | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
| golang | go | >= 1.21.0, < 1.21.3 | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
| golang | http2 | < 0.17.0 | cpe:2.3:a:golang:http2:*:*:*:*:*:go:*:* |
| golang | networking | < 0.17.0 | cpe:2.3:a:golang:networking:*:*:*:*:*:go:*:* |
| f5 | big-ip_access_policy_manager | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 17.1.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_web_application_firewall | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_web_application_firewall | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | 17.1.0 | cpe:2.3:a:f5:big-ip_analytics:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | 17.1.0 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 17.1.0 | cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_visibility_and_reporting | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_visibility_and_reporting | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_visibility_and_reporting | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_visibility_and_reporting | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_visibility_and_reporting | 17.1.0 | cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_carrier-grade_nat | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:* |
| f5 | big-ip_carrier-grade_nat | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:* |
| f5 | big-ip_carrier-grade_nat | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:* |
| f5 | big-ip_carrier-grade_nat | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:* |
| f5 | big-ip_carrier-grade_nat | 17.1.0 | cpe:2.3:a:f5:big-ip_carrier-grade_nat:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_ddos_hybrid_defender | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:* |
| f5 | big-ip_ddos_hybrid_defender | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:* |
| f5 | big-ip_ddos_hybrid_defender | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:* |
| f5 | big-ip_ddos_hybrid_defender | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:* |
| f5 | big-ip_ddos_hybrid_defender | 17.1.0 | cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_domain_name_system | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* |
| f5 | big-ip_domain_name_system | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* |
| f5 | big-ip_domain_name_system | >= 15.1.0, <= 15.1.10 | cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* |
| f5 | big-ip_domain_name_system | >= 16.1.0, <= 16.1.4 | cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* |
| f5 | big-ip_domain_name_system | 17.1.0 | cpe:2.3:a:f5:big-ip_domain_name_system:17.1.0:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | >= 13.1.0, <= 13.1.5 | cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | >= 14.1.0, <= 14.1.5 | cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* |