The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
292
Affected Products
287
References
ietf / http
| - |
| envoyproxy | envoy | - | - |
| envoyproxy | envoy | - | - |
| envoyproxy | envoy | - | - |
| envoyproxy | envoy | - | - |
| eclipse | jetty | 9.4.53 | - |
| eclipse | jetty | 10.0.0 - 10.0.17 | - |
| eclipse | jetty | 11.0.0 - 11.0.17 | - |
| eclipse | jetty | 12.0.0 - 12.0.2 | - |
| caddyserver | caddy | 2.7.5 | - |
| golang | go | 1.20.10 | - |
| golang | go | 1.21.0 - 1.21.3 | - |
| golang | http2 | 0.17.0 | - |
| golang | networking | 0.17.0 | - |
| f5 | big-ip_access_policy_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_access_policy_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_access_policy_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_access_policy_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_access_policy_manager | - | - |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_advanced_firewall_manager | - | - |
| f5 | big-ip_advanced_web_application_firewall | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_advanced_web_application_firewall | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_advanced_web_application_firewall | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_advanced_web_application_firewall | - | - |
| f5 | big-ip_analytics | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_analytics | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_analytics | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_analytics | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_analytics | - | - |
| f5 | big-ip_application_acceleration_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_application_acceleration_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_application_acceleration_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_application_acceleration_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_application_acceleration_manager | - | - |
| f5 | big-ip_application_security_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_application_security_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_application_security_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_application_security_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_application_security_manager | - | - |
| f5 | big-ip_application_visibility_and_reporting | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_application_visibility_and_reporting | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_application_visibility_and_reporting | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_application_visibility_and_reporting | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_application_visibility_and_reporting | - | - |
| f5 | big-ip_carrier-grade_nat | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_carrier-grade_nat | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_carrier-grade_nat | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_carrier-grade_nat | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_carrier-grade_nat | - | - |
| f5 | big-ip_ddos_hybrid_defender | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_ddos_hybrid_defender | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_ddos_hybrid_defender | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_ddos_hybrid_defender | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_ddos_hybrid_defender | - | - |
| f5 | big-ip_domain_name_system | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_domain_name_system | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_domain_name_system | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_domain_name_system | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_domain_name_system | - | - |
| f5 | big-ip_fraud_protection_service | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_fraud_protection_service | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_fraud_protection_service | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_fraud_protection_service | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_fraud_protection_service | - | - |
| f5 | big-ip_global_traffic_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_global_traffic_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_global_traffic_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_global_traffic_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_global_traffic_manager | - | - |
| f5 | big-ip_link_controller | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_link_controller | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_link_controller | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_link_controller | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_link_controller | - | - |
| f5 | big-ip_local_traffic_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_local_traffic_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_local_traffic_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_local_traffic_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_local_traffic_manager | - | - |
| f5 | big-ip_next | - | - |
| f5 | big-ip_next_service_proxy_for_kubernetes | 1.5.0 - 1.8.2 | - |
| f5 | big-ip_policy_enforcement_manager | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_policy_enforcement_manager | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_policy_enforcement_manager | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_policy_enforcement_manager | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_policy_enforcement_manager | - | - |
| f5 | big-ip_ssl_orchestrator | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_ssl_orchestrator | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_ssl_orchestrator | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_ssl_orchestrator | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_ssl_orchestrator | - | - |
| f5 | big-ip_webaccelerator | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_webaccelerator | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_webaccelerator | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_webaccelerator | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_webaccelerator | - | - |
| f5 | big-ip_websafe | 13.1.0 - 13.1.5 | - |
| f5 | big-ip_websafe | 14.1.0 - 14.1.5 | - |
| f5 | big-ip_websafe | 15.1.0 - 15.1.10 | - |
| f5 | big-ip_websafe | 16.1.0 - 16.1.4 | - |
| f5 | big-ip_websafe | - | - |
| f5 | nginx | 1.9.5 - 1.25.2 | - |
| f5 | nginx_ingress_controller | 2.0.0 - 2.4.2 | - |
| f5 | nginx_ingress_controller | 3.0.0 - 3.3.0 | - |
| f5 | nginx_plus | r25 - r29 | - |
| f5 | nginx_plus | - | - |
| f5 | nginx_plus | - | - |
| apache | tomcat | 8.5.0 - 8.5.93 | - |
| apache | tomcat | 9.0.0 - 9.0.80 | - |
| apache | tomcat | 10.1.0 - 10.1.13 | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apple | swiftnio_http\/2 | 1.28.0 | - |
| grpc | grpc | 1.56.3 | - |
| grpc | grpc | 1.59.2 | - |
| grpc | grpc | 1.58.0 - 1.58.3 | - |
| grpc | grpc | - | - |
| microsoft | .net | 6.0.0 - 6.0.23 | - |
| microsoft | .net | 7.0.0 - 7.0.12 | - |
| microsoft | asp.net_core | 6.0.0 - 6.0.23 | - |
| microsoft | asp.net_core | 7.0.0 - 7.0.12 | - |
| microsoft | azure_kubernetes_service | 2023-10-08 | - |
| microsoft | visual_studio_2022 | 17.0 - 17.2.20 | - |
| microsoft | visual_studio_2022 | 17.4 - 17.4.12 | - |
| microsoft | visual_studio_2022 | 17.6 - 17.6.8 | - |
| microsoft | visual_studio_2022 | 17.7 - 17.7.5 | - |
| microsoft | windows_10_1607 | 10.0.14393.6351 | - |
| microsoft | windows_10_1607 | 10.0.14393.6351 | - |
| microsoft | windows_10_1809 | 10.0.17763.4974 | - |
| microsoft | windows_10_21h2 | 10.0.19044.3570 | - |
| microsoft | windows_10_22h2 | 10.0.19045.3570 | - |
| microsoft | windows_11_21h2 | 10.0.22000.2538 | - |
| microsoft | windows_11_22h2 | 10.0.22621.2428 | - |
| microsoft | windows_server_2016 | - | - |
| microsoft | windows_server_2019 | - | - |
| microsoft | windows_server_2022 | - | - |
| nodejs | node.js | 18.0.0 - 18.18.2 | - |
| nodejs | node.js | 20.0.0 - 20.8.1 | - |
| microsoft | cbl-mariner | 2023-10-11 | - |
| dena | h2o | 2023-10-10 | - |
| proxygen | 2023.10.16.00 | - |
| apache | apisix | 3.6.1 | - |
| apache | traffic_server | 8.0.0 - 8.1.9 | - |
| apache | traffic_server | 9.0.0 - 9.2.3 | - |
| amazon | opensearch_data_prepper | 2.5.0 | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - | - |
| kazu-yamamoto | http2 | 4.2.2 | - |
| istio | istio | 1.17.6 | - |
| istio | istio | 1.18.0 - 1.18.3 | - |
| istio | istio | 1.19.0 - 1.19.1 | - |
| varnish_cache_project | varnish_cache | 2023-10-10 | - |
| traefik | traefik | 2.10.5 | - |
| traefik | traefik | - | - |
| traefik | traefik | - | - |
| traefik | traefik | - | - |
| projectcontour | contour | 2023-10-11 | - |
| linkerd | linkerd | 2.12.0 - 2.12.5 | - |
| linkerd | linkerd | - | - |
| linkerd | linkerd | - | - |
| linkerd | linkerd | - | - |
| linkerd | linkerd | - | - |
| linecorp | armeria | 1.26.0 | - |
| redhat | 3scale_api_management_platform | - | - |
| redhat | advanced_cluster_management_for_kubernetes | - | - |
| redhat | advanced_cluster_security | - | - |
| redhat | advanced_cluster_security | - | - |
| redhat | ansible_automation_platform | - | - |
| redhat | build_of_optaplanner | - | - |
| redhat | build_of_quarkus | - | - |
| redhat | ceph_storage | - | - |
| redhat | cert-manager_operator_for_red_hat_openshift | - | - |
| redhat | certification_for_red_hat_enterprise_linux | - | - |
| redhat | certification_for_red_hat_enterprise_linux | - | - |
| redhat | cost_management | - | - |
| redhat | cryostat | - | - |
| redhat | decision_manager | - | - |
| redhat | fence_agents_remediation_operator | - | - |
| redhat | integration_camel_for_spring_boot | - | - |
| redhat | integration_camel_k | - | - |
| redhat | integration_service_registry | - | - |
| redhat | jboss_a-mq | - | - |
| redhat | jboss_a-mq_streams | - | - |
| redhat | jboss_core_services | - | - |
| redhat | jboss_data_grid | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| redhat | jboss_enterprise_application_platform | - | - |
| redhat | jboss_fuse | - | - |
| redhat | jboss_fuse | - | - |
| redhat | logging_subsystem_for_red_hat_openshift | - | - |
| redhat | machine_deletion_remediation_operator | - | - |
| redhat | migration_toolkit_for_applications | - | - |
| redhat | migration_toolkit_for_containers | - | - |
| redhat | migration_toolkit_for_virtualization | - | - |
| redhat | network_observability_operator | - | - |
| redhat | node_healthcheck_operator | - | - |
| redhat | node_maintenance_operator | - | - |
| redhat | openshift | - | - |
| redhat | openshift_api_for_data_protection | - | - |
| redhat | openshift_container_platform | - | - |
| redhat | openshift_container_platform_assisted_installer | - | - |
| redhat | openshift_data_science | - | - |
| redhat | openshift_dev_spaces | - | - |
| redhat | openshift_developer_tools_and_services | - | - |
| redhat | openshift_distributed_tracing | - | - |
| redhat | openshift_gitops | - | - |
| redhat | openshift_pipelines | - | - |
| redhat | openshift_sandboxed_containers | - | - |
| redhat | openshift_secondary_scheduler_operator | - | - |
| redhat | openshift_serverless | - | - |
| redhat | openshift_service_mesh | - | - |
| redhat | openshift_virtualization | - | - |
| redhat | openstack_platform | - | - |
| redhat | openstack_platform | - | - |
| redhat | openstack_platform | - | - |
| redhat | process_automation | - | - |
| redhat | quay | - | - |
| redhat | run_once_duration_override_operator | - | - |
| redhat | satellite | - | - |
| redhat | self_node_remediation_operator | - | - |
| redhat | service_interconnect | - | - |
| redhat | single_sign-on | - | - |
| redhat | support_for_spring_boot | - | - |
| redhat | web_terminal | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux | - | - |
| redhat | service_telemetry_framework | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| netapp | astra_control_center | - | - |
| netapp | oncommand_insight | - | - |
| akka | http_server | 10.5.3 | - |
| konghq | kong_gateway | 3.4.2 | - |
| jenkins | jenkins | 2.414.2 | - |
| jenkins | jenkins | 2.427 | - |
| apache | solr | 9.4.0 | - |
| openresty | openresty | 1.21.4.3 | - |
| cisco | business_process_automation | 3.2.003.009 | - |
| cisco | connected_mobile_experiences | 11.1 | - |
| cisco | crosswork_data_gateway | 4.1.3 | - |
| cisco | crosswork_data_gateway | 5.0.0 - 5.0.2 | - |
| cisco | crosswork_situation_manager | - | - |
| cisco | crosswork_zero_touch_provisioning | 6.0.0 | - |
| cisco | data_center_network_manager | - | - |
| cisco | enterprise_chat_and_email | - | - |
| cisco | expressway | x14.3.3 | - |
| cisco | firepower_threat_defense | 7.4.2 | - |
| cisco | iot_field_network_director | 4.11.0 | - |
| cisco | prime_access_registrar | 9.3.3 | - |
| cisco | prime_cable_provisioning | 7.2.1 | - |
| cisco | prime_infrastructure | 3.10.4 | - |
| cisco | prime_network_registrar | 11.2 | - |
| cisco | secure_dynamic_attributes_connector | 2.2.0 | - |
| cisco | secure_malware_analytics | 2.19.2 | - |
| cisco | telepresence_video_communication_server | x14.3.3 | - |
| cisco | ultra_cloud_core_-_policy_control_function | 2024.01.0 | - |
| cisco | ultra_cloud_core_-_policy_control_function | - | - |
| cisco | ultra_cloud_core_-_serving_gateway_function | 2024.02.0 | - |
| cisco | ultra_cloud_core_-_session_management_function | 2024.02.0 | - |
| cisco | unified_attendant_console_advanced | - | - |
| cisco | unified_contact_center_domain_manager | - | - |
| cisco | unified_contact_center_enterprise | - | - |
| cisco | unified_contact_center_enterprise_-_live_data_server | 12.6.2 | - |
| cisco | unified_contact_center_management_portal | - | - |
| cisco | fog_director | 1.22 | - |
| cisco | ios_xe | 17.15.1 | - |
| cisco | ios_xr | 7.11.2 | - |
| cisco | secure_web_appliance_firmware | 15.1.0 | - |
| cisco | nx-os | 10.2\(7\) | - |
| cisco | nx-os | 10.3\(1\) - 10.3\(5\) | - |
| cisco | nx-os | 10.4\(1\) - 10.4\(2\) | - |
| cisco | nx-os | 10.2\(7\) | - |
| cisco | nx-os | 10.3\(1\) - 10.3\(5\) | - |
| cisco | nx-os | 10.4\(1\) - 10.4\(2\) | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability
Impact