The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Loading...
Loading...
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-10-10), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.5 retained for reference. Confidence: HIGH.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
October 10, 2023
May 12, 2026
These vendors published their own advisory mentioning this CVE โ often with vendor-specific remediation steps + affected product lists not in NVD.
Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.4 security update
Red Hat Security Advisory: OpenShift Virtualization 4.14.0 Images security and bug fix update
Red Hat Security Advisory: OpenShift Container Platform 4.14.0 bug fix and security update
GitLab Security Release: 16.5.1, 16.4.2, 16.3.6
See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-44487
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
redhat ยท ubuntu