CVE-2023-44487
10.10.2023, 14:15
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.Enginsight
Vendor | Product | Version |
---|---|---|
ietf | http | 2.0 |
nghttp2 | nghttp2 | 𝑥 < 1.57.0 |
netty | netty | 𝑥 < 4.1.100 |
envoyproxy | envoy | 1.24.10 |
envoyproxy | envoy | 1.25.9 |
envoyproxy | envoy | 1.26.4 |
envoyproxy | envoy | 1.27.0 |
eclipse | jetty | 𝑥 < 9.4.53 |
eclipse | jetty | 10.0.0 ≤ 𝑥 < 10.0.17 |
eclipse | jetty | 11.0.0 ≤ 𝑥 < 11.0.17 |
eclipse | jetty | 12.0.0 ≤ 𝑥 < 12.0.2 |
caddyserver | caddy | 𝑥 < 2.7.5 |
golang | go | 𝑥 < 1.20.10 |
golang | go | 1.21.0 ≤ 𝑥 < 1.21.3 |
golang | http2 | 𝑥 < 0.17.0 |
golang | networking | 𝑥 < 0.17.0 |
f5 | big-ip_access_policy_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_access_policy_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_access_policy_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_access_policy_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_access_policy_manager | 17.1.0 |
f5 | big-ip_advanced_firewall_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_advanced_firewall_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_advanced_firewall_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_advanced_firewall_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_advanced_firewall_manager | 17.1.0 |
f5 | big-ip_advanced_web_application_firewall | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_advanced_web_application_firewall | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_advanced_web_application_firewall | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_advanced_web_application_firewall | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_advanced_web_application_firewall | 17.1.0 |
f5 | big-ip_analytics | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_analytics | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_analytics | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_analytics | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_analytics | 17.1.0 |
f5 | big-ip_application_acceleration_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_application_acceleration_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_application_acceleration_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_application_acceleration_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_application_acceleration_manager | 17.1.0 |
f5 | big-ip_application_security_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_application_security_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_application_security_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_application_security_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_application_security_manager | 17.1.0 |
f5 | big-ip_application_visibility_and_reporting | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_application_visibility_and_reporting | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_application_visibility_and_reporting | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_application_visibility_and_reporting | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_application_visibility_and_reporting | 17.1.0 |
f5 | big-ip_carrier-grade_nat | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_carrier-grade_nat | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_carrier-grade_nat | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_carrier-grade_nat | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_carrier-grade_nat | 17.1.0 |
f5 | big-ip_ddos_hybrid_defender | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_ddos_hybrid_defender | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_ddos_hybrid_defender | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_ddos_hybrid_defender | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_ddos_hybrid_defender | 17.1.0 |
f5 | big-ip_domain_name_system | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_domain_name_system | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_domain_name_system | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_domain_name_system | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_domain_name_system | 17.1.0 |
f5 | big-ip_fraud_protection_service | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_fraud_protection_service | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_fraud_protection_service | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_fraud_protection_service | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_fraud_protection_service | 17.1.0 |
f5 | big-ip_global_traffic_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_global_traffic_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_global_traffic_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_global_traffic_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_global_traffic_manager | 17.1.0 |
f5 | big-ip_link_controller | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_link_controller | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_link_controller | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_link_controller | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_link_controller | 17.1.0 |
f5 | big-ip_local_traffic_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_local_traffic_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_local_traffic_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_local_traffic_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_local_traffic_manager | 17.1.0 |
f5 | big-ip_next | 20.0.1 |
f5 | big-ip_next_service_proxy_for_kubernetes | 1.5.0 ≤ 𝑥 ≤ 1.8.2 |
f5 | big-ip_policy_enforcement_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_policy_enforcement_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_policy_enforcement_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_policy_enforcement_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_policy_enforcement_manager | 17.1.0 |
f5 | big-ip_ssl_orchestrator | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_ssl_orchestrator | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_ssl_orchestrator | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_ssl_orchestrator | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_ssl_orchestrator | 17.1.0 |
f5 | big-ip_webaccelerator | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_webaccelerator | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_webaccelerator | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_webaccelerator | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_webaccelerator | 17.1.0 |
f5 | big-ip_websafe | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_websafe | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_websafe | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_websafe | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_websafe | 17.1.0 |
f5 | nginx | 1.9.5 ≤ 𝑥 ≤ 1.25.2 |
f5 | nginx_ingress_controller | 2.0.0 ≤ 𝑥 ≤ 2.4.2 |
f5 | nginx_ingress_controller | 3.0.0 ≤ 𝑥 ≤ 3.3.0 |
f5 | nginx_plus | r25 ≤ 𝑥 < r29 |
apache | tomcat | 8.5.0 ≤ 𝑥 ≤ 8.5.93 |
apache | tomcat | 9.0.0 ≤ 𝑥 ≤ 9.0.80 |
apache | tomcat | 10.1.0 ≤ 𝑥 ≤ 10.1.13 |
apache | tomcat | 11.0.0:milestone1 |
apache | tomcat | 11.0.0:milestone10 |
apache | tomcat | 11.0.0:milestone11 |
apache | tomcat | 11.0.0:milestone2 |
apache | tomcat | 11.0.0:milestone3 |
apache | tomcat | 11.0.0:milestone4 |
apache | tomcat | 11.0.0:milestone5 |
apache | tomcat | 11.0.0:milestone6 |
apache | tomcat | 11.0.0:milestone7 |
apache | tomcat | 11.0.0:milestone8 |
apache | tomcat | 11.0.0:milestone9 |
apple | swiftnio_http\/2 | 𝑥 < 1.28.0 |
grpc | grpc | 𝑥 < 1.56.3 |
grpc | grpc | 𝑥 ≤ 1.59.2 |
grpc | grpc | 1.58.0 ≤ 𝑥 < 1.58.3 |
grpc | grpc | 1.57.0 |
microsoft | .net | 6.0.0 ≤ 𝑥 < 6.0.23 |
microsoft | .net | 7.0.0 ≤ 𝑥 < 7.0.12 |
microsoft | asp.net_core | 6.0.0 ≤ 𝑥 < 6.0.23 |
microsoft | asp.net_core | 7.0.0 ≤ 𝑥 < 7.0.12 |
microsoft | azure_kubernetes_service | 𝑥 < 2023-10-08 |
microsoft | visual_studio_2022 | 17.0 ≤ 𝑥 < 17.2.20 |
microsoft | visual_studio_2022 | 17.4 ≤ 𝑥 < 17.4.12 |
microsoft | visual_studio_2022 | 17.6 ≤ 𝑥 < 17.6.8 |
microsoft | visual_studio_2022 | 17.7 ≤ 𝑥 < 17.7.5 |
microsoft | windows_10_1607 | 𝑥 < 10.0.14393.6351 |
microsoft | windows_10_1607 | 𝑥 < 10.0.14393.6351 |
microsoft | windows_10_1809 | 𝑥 < 10.0.17763.4974 |
microsoft | windows_10_21h2 | 𝑥 < 10.0.19044.3570 |
microsoft | windows_10_22h2 | 𝑥 < 10.0.19045.3570 |
microsoft | windows_11_21h2 | 𝑥 < 10.0.22000.2538 |
microsoft | windows_11_22h2 | 𝑥 < 10.0.22621.2428 |
microsoft | windows_server_2016 | - |
microsoft | windows_server_2019 | - |
microsoft | windows_server_2022 | - |
nodejs | node.js | 18.0.0 ≤ 𝑥 < 18.18.2 |
nodejs | node.js | 20.0.0 ≤ 𝑥 < 20.8.1 |
microsoft | cbl-mariner | 𝑥 < 2023-10-11 |
dena | h2o | 𝑥 < 2023-10-10 |
proxygen | 𝑥 < 2023.10.16.00 | |
apache | apisix | 𝑥 < 3.6.1 |
apache | traffic_server | 8.0.0 ≤ 𝑥 < 8.1.9 |
apache | traffic_server | 9.0.0 ≤ 𝑥 < 9.2.3 |
amazon | opensearch_data_prepper | 𝑥 < 2.5.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
kazu-yamamoto | http2 | 𝑥 < 4.2.2 |
istio | istio | 𝑥 < 1.17.6 |
istio | istio | 1.18.0 ≤ 𝑥 < 1.18.3 |
istio | istio | 1.19.0 ≤ 𝑥 < 1.19.1 |
varnish_cache_project | varnish_cache | 𝑥 < 2023-10-10 |
traefik | traefik | 𝑥 < 2.10.5 |
traefik | traefik | 3.0.0:beta1 |
traefik | traefik | 3.0.0:beta2 |
traefik | traefik | 3.0.0:beta3 |
projectcontour | contour | 𝑥 < 2023-10-11 |
linkerd | linkerd | 2.12.0 ≤ 𝑥 ≤ 2.12.5 |
linkerd | linkerd | 2.13.0 |
linkerd | linkerd | 2.13.1 |
linkerd | linkerd | 2.14.0 |
linkerd | linkerd | 2.14.1 |
linecorp | armeria | 𝑥 < 1.26.0 |
redhat | 3scale_api_management_platform | 2.0 |
redhat | advanced_cluster_management_for_kubernetes | 2.0 |
redhat | advanced_cluster_security | 3.0 |
redhat | advanced_cluster_security | 4.0 |
redhat | ansible_automation_platform | 2.0 |
redhat | build_of_optaplanner | 8.0 |
redhat | build_of_quarkus | - |
redhat | ceph_storage | 5.0 |
redhat | cert-manager_operator_for_red_hat_openshift | - |
redhat | certification_for_red_hat_enterprise_linux | 8.0 |
redhat | certification_for_red_hat_enterprise_linux | 9.0 |
redhat | cost_management | - |
redhat | cryostat | 2.0 |
redhat | decision_manager | 7.0 |
redhat | fence_agents_remediation_operator | - |
redhat | integration_camel_for_spring_boot | - |
redhat | integration_camel_k | - |
redhat | integration_service_registry | - |
redhat | jboss_a-mq_streams | - |
redhat | jboss_core_services | - |
redhat | jboss_data_grid | 7.0.0 |
redhat | jboss_enterprise_application_platform | 6.0.0 |
redhat | jboss_enterprise_application_platform | 7.0.0 |
redhat | jboss_fuse | 6.0.0 |
redhat | jboss_fuse | 7.0.0 |
redhat | logging_subsystem_for_red_hat_openshift | - |
redhat | machine_deletion_remediation_operator | - |
redhat | migration_toolkit_for_applications | 6.0 |
redhat | migration_toolkit_for_containers | - |
redhat | migration_toolkit_for_virtualization | - |
redhat | network_observability_operator | - |
redhat | node_healthcheck_operator | - |
redhat | node_maintenance_operator | - |
redhat | openshift | - |
redhat | openshift_api_for_data_protection | - |
redhat | openshift_container_platform | 4.0 |
redhat | openshift_container_platform_assisted_installer | - |
redhat | openshift_data_science | - |
redhat | openshift_dev_spaces | - |
redhat | openshift_developer_tools_and_services | - |
redhat | openshift_distributed_tracing | - |
redhat | openshift_gitops | - |
redhat | openshift_pipelines | - |
redhat | openshift_sandboxed_containers | - |
redhat | openshift_secondary_scheduler_operator | - |
redhat | openshift_serverless | - |
redhat | openshift_service_mesh | 2.0 |
redhat | openstack_platform | 16.1 |
redhat | openstack_platform | 16.2 |
redhat | openstack_platform | 17.1 |
redhat | process_automation | 7.0 |
redhat | quay | 3.0.0 |
redhat | run_once_duration_override_operator | - |
redhat | satellite | 6.0 |
redhat | self_node_remediation_operator | - |
redhat | service_interconnect | 1.0 |
redhat | single_sign-on | 7.0 |
redhat | support_for_spring_boot | - |
redhat | web_terminal | - |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
redhat | service_telemetry_framework | 1.5 |
netapp | astra_control_center | - |
netapp | oncommand_insight | - |
akka | http_server | 𝑥 < 10.5.3 |
konghq | kong_gateway | 𝑥 < 3.4.2 |
jenkins | jenkins | 𝑥 ≤ 2.414.2 |
jenkins | jenkins | 𝑥 ≤ 2.427 |
apache | solr | 𝑥 < 9.4.0 |
openresty | openresty | 𝑥 < 1.21.4.3 |
cisco | connected_mobile_experiences | 𝑥 < 11.1 |
cisco | crosswork_data_gateway | 𝑥 < 4.1.3 |
cisco | crosswork_data_gateway | 5.0 |
cisco | crosswork_zero_touch_provisioning | 𝑥 < 6.0.0 |
cisco | data_center_network_manager | - |
cisco | enterprise_chat_and_email | - |
cisco | firepower_threat_defense | 𝑥 < 7.4.2 |
cisco | iot_field_network_director | 𝑥 < 4.11.0 |
cisco | prime_access_registrar | 𝑥 < 9.3.3 |
cisco | prime_cable_provisioning | 𝑥 < 7.2.1 |
cisco | prime_infrastructure | 𝑥 < 3.10.4 |
cisco | prime_network_registrar | 𝑥 < 11.2 |
cisco | secure_dynamic_attributes_connector | 𝑥 < 2.2.0 |
cisco | secure_malware_analytics | 𝑥 < 2.19.2 |
cisco | ultra_cloud_core_-_policy_control_function | 𝑥 < 2024.01.0 |
cisco | ultra_cloud_core_-_policy_control_function | 2024.01.0 |
cisco | ultra_cloud_core_-_serving_gateway_function | 𝑥 < 2024.02.0 |
cisco | ultra_cloud_core_-_session_management_function | 𝑥 < 2024.02.0 |
cisco | unified_attendant_console_advanced | - |
cisco | unified_contact_center_domain_manager | - |
cisco | unified_contact_center_enterprise | - |
cisco | unified_contact_center_enterprise_-_live_data_server | 𝑥 < 12.6.2 |
cisco | unified_contact_center_management_portal | - |
cisco | fog_director | 𝑥 < 1.22 |
cisco | ios_xe | 𝑥 < 17.15.1 |
cisco | ios_xr | 𝑥 < 7.11.2 |
cisco | secure_web_appliance_firmware | 𝑥 < 15.1.0 |
cisco | nx-os | 𝑥 < 10.2\(7\) |
cisco | nx-os | 10.3\(1\) ≤ 𝑥 < 10.3\(5\) |
cisco | nx-os | 𝑥 < 10.2\(7\) |
cisco | nx-os | 10.3\(1\) ≤ 𝑥 < 10.3\(5\) |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
dnsdist |
| ||||||||||||||
grpc |
| ||||||||||||||
h2o |
| ||||||||||||||
haproxy |
| ||||||||||||||
jetty9 |
| ||||||||||||||
netty |
| ||||||||||||||
nghttp2 |
| ||||||||||||||
nginx |
| ||||||||||||||
tomcat10 |
| ||||||||||||||
tomcat9 |
| ||||||||||||||
trafficserver |
| ||||||||||||||
varnish |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
dotnet6 |
| ||||||||||||||||||||
dotnet7 |
| ||||||||||||||||||||
dotnet8 |
| ||||||||||||||||||||
h2o |
| ||||||||||||||||||||
haproxy |
| ||||||||||||||||||||
netty |
| ||||||||||||||||||||
nghttp2 |
| ||||||||||||||||||||
nginx |
| ||||||||||||||||||||
nodejs |
| ||||||||||||||||||||
tomcat10 |
| ||||||||||||||||||||
tomcat8 |
| ||||||||||||||||||||
tomcat9 |
| ||||||||||||||||||||
trafficserver |
|