Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- Akka / http_server10.5.3
- Amazon / opensearch_data_prepper2.5.0
- apache / apisix3.6.1
- apache / Solr9.4.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat8.5.0 – 8.5.93
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / Tomcat11.0.0 – 11.0.0
- apache / traffic_server8.0.0 – 8.1.9
- Apple / swiftnio_http/21.28.0
- caddyserver / caddy2.7.5
- Cisco / business_process_automation3.2.003.009
- Cisco / connected_mobile_experiences11.1
- Cisco / crosswork_data_gateway4.1.3
- Cisco / crosswork_situation_manager
- Cisco / crosswork_zero_touch_provisioning6.0.0
- Cisco / data_center_network_manager
- Cisco / enterprise_chat_and_email
- Cisco / expresswayx14.3.3
- Cisco / fog_director1.22
- Cisco / ios_xe17.15.1
- Cisco / ios_xr7.11.2
- Cisco / iot_field_network_director4.11.0
- Cisco / nx-os10.2\(7\)
- Cisco / prime_access_registrar9.3.3
- Cisco / prime_cable_provisioning7.2.1
- Cisco / prime_infrastructure3.10.4
- Cisco / prime_network_registrar11.2
- Cisco / secure_dynamic_attributes_connector2.2.0
- Cisco / secure_firewall_threat_defense7.4.2
- Cisco / secure_malware_analytics2.19.2
- Cisco / secure_web_appliance_firmware15.1.0
- Cisco / telepresence_video_communication_serverx14.3.3
- Cisco / ultra_cloud_core_-_policy_control_function2024.01.0
- Cisco / ultra_cloud_core_-_policy_control_function2024.01.0 – 2024.01.0
- Cisco / ultra_cloud_core_-_serving_gateway_function2024.02.0
- Cisco / ultra_cloud_core_-_session_management_function2024.02.0
- Cisco / unified_attendant_console_advanced
- Cisco / unified_contact_center_domain_manager
- Cisco / unified_contact_center_enterprise
- Cisco / unified_contact_center_enterprise_-_live_data_server12.6.2
- Cisco / unified_contact_center_management_portal
- debian / debian_linux10.0 – 10.0
- debian / debian_linux12.0 – 12.0
- debian / debian_linux11.0 – 11.0
- dena / h2o2023-10-10
- Eclipse / jetty9.4.53
- envoyproxy / envoy1.24.10 – 1.24.10
- envoyproxy / envoy1.25.9 – 1.25.9
- envoyproxy / envoy1.26.4 – 1.26.4
- envoyproxy / envoy1.27.0 – 1.27.0
- F5 / big-ip_access_policy_manager13.1.0 – 13.1.5
- F5 / big-ip_access_policy_manager17.1.0 – 17.1.0
- F5 / big-ip_advanced_firewall_manager13.1.0 – 13.1.5
- F5 / big-ip_advanced_firewall_manager17.1.0 – 17.1.0
- F5 / big-ip_advanced_web_application_firewall17.1.0 – 17.1.0
- F5 / big-ip_advanced_web_application_firewall13.1.0 – 13.1.5
- F5 / big-ip_analytics13.1.0 – 13.1.5
- F5 / big-ip_analytics17.1.0 – 17.1.0
- F5 / big-ip_application_acceleration_manager13.1.0 – 13.1.5
- F5 / big-ip_application_acceleration_manager17.1.0 – 17.1.0
- F5 / big-ip_application_security_manager17.1.0 – 17.1.0
- F5 / big-ip_application_security_manager13.1.0 – 13.1.5
- F5 / big-ip_application_visibility_and_reporting13.1.0 – 13.1.5
- F5 / big-ip_application_visibility_and_reporting17.1.0 – 17.1.0
- F5 / big-ip_carrier-grade_nat17.1.0 – 17.1.0
- F5 / big-ip_carrier-grade_nat13.1.0 – 13.1.5
- F5 / big-ip_ddos_hybrid_defender13.1.0 – 13.1.5
- F5 / big-ip_ddos_hybrid_defender17.1.0 – 17.1.0
- F5 / big-ip_domain_name_system13.1.0 – 13.1.5
- F5 / big-ip_domain_name_system17.1.0 – 17.1.0
- F5 / big-ip_fraud_protection_service17.1.0 – 17.1.0
- F5 / big-ip_fraud_protection_service13.1.0 – 13.1.5
- F5 / big-ip_global_traffic_manager17.1.0 – 17.1.0
- F5 / big-ip_global_traffic_manager13.1.0 – 13.1.5
- F5 / big-ip_link_controller17.1.0 – 17.1.0
- F5 / big-ip_link_controller13.1.0 – 13.1.5
- F5 / big-ip_local_traffic_manager17.1.0 – 17.1.0
- F5 / big-ip_local_traffic_manager13.1.0 – 13.1.5
- F5 / BIG-IP Next20.0.1 – 20.0.1
- F5 / big-ip_next_service_proxy_for_kubernetes1.5.0 – 1.8.2
- F5 / big-ip_policy_enforcement_manager17.1.0 – 17.1.0
- F5 / big-ip_policy_enforcement_manager13.1.0 – 13.1.5
- F5 / big-ip_ssl_orchestrator13.1.0 – 13.1.5
- F5 / big-ip_ssl_orchestrator17.1.0 – 17.1.0
- F5 / big-ip_webaccelerator13.1.0 – 13.1.5
- F5 / big-ip_webaccelerator17.1.0 – 17.1.0
- F5 / big-ip_websafe17.1.0 – 17.1.0
- F5 / big-ip_websafe13.1.0 – 13.1.5
- F5 / NGINX1.9.5 – 1.25.2
- F5 / NGINX Ingress Controller2.0.0 – 2.4.2
- F5 / NGINX Plusr30 – r30
- F5 / NGINX Plusr25 – r29
- F5 / NGINX Plusr29 – r29
- Facebook / proxygen2023.10.16.00
- fedoraproject / fedora37 – 37
- fedoraproject / fedora38 – 38
- Golang / Go1.20.10
- Golang / http20.17.0
- Golang / networking0.17.0
- grpc / grpc1.56.3
- grpc / grpc1.57.0 – 1.57.0
- grpc / grpc1.59.2
- IETF / http2.0 – 2.0
- istio / istio1.17.6
- Jenkins / jenkins2.414.2
- Jenkins / jenkins2.427
- kazu-yamamoto / http24.2.2
- KongHQ / kong_gateway3.4.2
- linecorp / armeria1.26.0
- linkerd / linkerd2.13.0 – 2.13.0
- linkerd / linkerd2.12.0 – 2.12.5
- linkerd / linkerd2.13.1 – 2.13.1
- linkerd / linkerd2.14.0 – 2.14.0
- linkerd / linkerd2.14.1 – 2.14.1
- microsoft / asp.net_core6.0.0 – 6.0.23
- microsoft / Azure Kubernetes Service2023-10-08
- microsoft / cbl_mariner2023-10-11
- microsoft / .net6.0.0 – 6.0.23
- microsoft / visual_studio_202217.0 – 17.2.20
- microsoft / windows_10_160710.0.14393.6351
- microsoft / windows_10_160710.0.14393.6351
- microsoft / windows_10_180910.0.17763.4974
- microsoft / windows_10_21H210.0.19044.3570
- microsoft / windows_10_22h210.0.19045.3570
- microsoft / windows_11_21H210.0.22000.2538
- microsoft / windows_11_22h210.0.22621.2428
- microsoft / Windows Server 2016
- microsoft / Windows Server 2019
- microsoft / Windows Server 2022
- NETAPP / astra_control_center
- NETAPP / OnCommand Insight
- netty / netty4.1.100
- nghttp2 / nghttp21.57.0
- nodejs / node.js18.0.0 – 18.18.2
- openresty / openresty1.21.4.3
- projectcontour / contour2023-10-11
- RedHat / 3scale_api_management_platform2.0 – 2.0
- RedHat / advanced_cluster_management_for_kubernetes2.0 – 2.0
- RedHat / advanced_cluster_security3.0 – 3.0
- RedHat / advanced_cluster_security4.0 – 4.0
- RedHat / ansible_automation_platform2.0 – 2.0
- RedHat / build_of_optaplanner8.0 – 8.0
- RedHat / build_of_quarkus
- RedHat / ceph_storage5.0 – 5.0
- RedHat / certification_for_red_hat_enterprise_linux8.0 – 8.0
- RedHat / certification_for_red_hat_enterprise_linux9.0 – 9.0
- RedHat / cert-manager_operator_for_red_hat_openshift
- RedHat / cost_management
- RedHat / cryostat2.0 – 2.0
- RedHat / decision_manager7.0 – 7.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / fence_agents_remediation_operator
- RedHat / integration_camel_for_spring_boot
- RedHat / integration_camel_k
- RedHat / integration_service_registry
- RedHat / jboss_a-mq7 – 7
- RedHat / jboss_a-mq_streams
- RedHat / jboss_core_services
- RedHat / jboss_data_grid7.0.0 – 7.0.0
- RedHat / jboss_enterprise_application_platform6.0.0 – 6.0.0
- RedHat / jboss_enterprise_application_platform7.0.0 – 7.0.0
- RedHat / jboss_fuse6.0.0 – 6.0.0
- RedHat / jboss_fuse7.0.0 – 7.0.0
- RedHat / logging_subsystem_for_red_hat_openshift
- RedHat / machine_deletion_remediation_operator
- RedHat / migration_toolkit_for_applications6.0 – 6.0
- RedHat / migration_toolkit_for_containers
- RedHat / migration_toolkit_for_virtualization
- RedHat / network_observability_operator
- RedHat / node_healthcheck_operator
- RedHat / node_maintenance_operator
- RedHat / openshift
- RedHat / openshift_api_for_data_protection
- RedHat / openshift_container_platform4.0 – 4.0
- RedHat / openshift_container_platform_assisted_installer
- RedHat / openshift_data_science
- RedHat / openshift_developer_tools_and_services
- RedHat / openshift_dev_spaces
- RedHat / openshift_distributed_tracing
- RedHat / openshift_gitops
- RedHat / openshift_pipelines
- RedHat / openshift_sandboxed_containers
- RedHat / openshift_secondary_scheduler_operator
- RedHat / openshift_serverless
- RedHat / openshift_service_mesh2.0 – 2.0
- RedHat / openshift_virtualization4 – 4
- RedHat / openstack_platform17.1 – 17.1
- RedHat / openstack_platform16.2 – 16.2
- RedHat / openstack_platform16.1 – 16.1
- RedHat / process_automation7.0 – 7.0
- RedHat / quay3.0.0 – 3.0.0
- RedHat / run_once_duration_override_operator
- RedHat / satellite6.0 – 6.0
- RedHat / self_node_remediation_operator
- RedHat / service_interconnect1.0 – 1.0
- RedHat / service_telemetry_framework1.5 – 1.5
- RedHat / single_sign-on7.0 – 7.0
- RedHat / support_for_spring_boot
- RedHat / web_terminal
- Siemens / ruggedcom_ape1808_firmware
- Siemens / simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware3.1.5 –
- Siemens / simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware3.1.5 –
- Siemens / SINEC INS1.0
- Siemens / SINEC INS1.0 – 1.0
- Siemens / SINEC INS1.0 – 1.0
- Siemens / SINEC INS1.0 – 1.0
- Siemens / SINEC INS1.0 – 1.0
- Siemens / SINEC INS1.0 – 1.0
- Siemens / SINEC NMS3.0
- Siemens / siplus_s7-1500_cpu_1518-4_pn/dp_mfp_firmware3.1.5 –
- Siemens / st7_scadaconnect1.1
- traefik / traefik3.0.0 – 3.0.0
- traefik / traefik3.0.0 – 3.0.0
- traefik / traefik2.10.5
- traefik / traefik3.0.0 – 3.0.0
- varnish_cache_project / varnish_cache2023-10-10
Exploits & proofs of concept
- exploit-dbHTTP/2 2.0 - Denial Of Service (DOS)by Madhusudhan Rajappa
References
- MISChttps://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73
- MISChttps://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- MISChttps://aws.amazon.com/security/security-bulletins/AWS-2023-011/
- MISChttps://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
- MISChttps://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
- MISChttps://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
- MISChttps://news.ycombinator.com/item?id=37831062
- MISChttps://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- MISChttps://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack
- PATCHhttps://github.com/envoyproxy/envoy/pull/30055
- MISChttps://github.com/haproxy/haproxy/issues/2312
- MISChttps://github.com/eclipse/jetty.project/issues/10679
- MISChttps://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764
- PATCHhttps://github.com/nghttp2/nghttp2/pull/1961
- PATCHhttps://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
- MISChttps://github.com/alibaba/tengine/issues/1872
- MISChttps://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2
- MISChttps://news.ycombinator.com/item?id=37830987
- MISChttps://news.ycombinator.com/item?id=37830998
- MISChttps://github.com/caddyserver/caddy/issues/5877
- MISChttps://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/
- MISChttps://github.com/bcdannyboy/CVE-2023-44487
- PATCHhttps://github.com/grpc/grpc-go/pull/6703
- MISChttps://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244
- PATCHhttps://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
- MAILING_LISThttps://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
- MISChttps://my.f5.com/manage/s/article/K000137106
- VENDOR_ADVISORYhttps://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
- MISChttps://bugzilla.proxmox.com/show_bug.cgi?id=4988
- MISChttps://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/10/7
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/10/6
- MISChttps://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected
- PATCHhttps://github.com/microsoft/CBL-Mariner/pull/6381
- MISChttps://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
- PATCHhttps://github.com/facebook/proxygen/pull/466
- MISChttps://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
- MISChttps://github.com/micrictor/http2-rst-stream
- MISChttps://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
- MISChttps://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/
- VENDOR_ADVISORYhttps://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
- PATCHhttps://github.com/h2o/h2o/pull/3291
- PATCHhttps://github.com/nodejs/node/pull/50121
- MISChttps://github.com/dotnet/announcements/issues/277
- MISChttps://github.com/golang/go/issues/63417
- VENDOR_ADVISORYhttps://github.com/advisories/GHSA-vx74-f528-fxqg
- PATCHhttps://github.com/apache/trafficserver/pull/10564
- VENDOR_ADVISORYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
- MISChttps://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
- MAILING_LISThttps://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
- MAILING_LISThttps://www.openwall.com/lists/oss-security/2023/10/10/6
- MISChttps://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
- MISChttps://github.com/opensearch-project/data-prepper/issues/3474
- PATCHhttps://github.com/kubernetes/kubernetes/pull/121120
- MISChttps://github.com/oqtane/oqtane.framework/discussions/3367
- VENDOR_ADVISORYhttps://github.com/advisories/GHSA-xpw8-rcwv-8f8p
- MISChttps://netty.io/news/2023/10/10/4-1-100-Final.html
- MISChttps://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
- MISChttps://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
- MISChttps://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack
- MISChttps://news.ycombinator.com/item?id=37837043
- MISChttps://github.com/kazu-yamamoto/http2/issues/93
- MISChttps://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html
- PATCHhttps://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1
- MISChttps://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113
- VENDOR_ADVISORYhttps://www.debian.org/security/2023/dsa-5522
- VENDOR_ADVISORYhttps://www.debian.org/security/2023/dsa-5521
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/cve-2023-44487
- MISChttps://github.com/ninenines/cowboy/issues/1615
- MISChttps://github.com/varnishcache/varnish-cache/issues/3996
- MISChttps://github.com/tempesta-tech/tempesta/issues/1986
- MISChttps://blog.vespa.ai/cve-2023-44487/
- MISChttps://github.com/etcd-io/etcd/issues/16740
- MISChttps://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event
- MISChttps://istio.io/latest/news/security/istio-security-2023-004/
- MISChttps://github.com/junkurihara/rust-rpxy/issues/97
- MISChttps://bugzilla.suse.com/show_bug.cgi?id=1216123
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- VENDOR_ADVISORYhttps://ubuntu.com/security/CVE-2023-44487
- MISChttps://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
- VENDOR_ADVISORYhttps://github.com/advisories/GHSA-qppj-fm5r-hxr3
- PATCHhttps://github.com/apache/httpd-site/pull/10
- PATCHhttps://github.com/projectcontour/contour/pull/5826
- PATCHhttps://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632
- PATCHhttps://github.com/line/armeria/pull/5232
- MISChttps://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
- MISChttps://security.paloaltonetworks.com/CVE-2023-44487
- MISChttps://github.com/akka/akka-http/issues/4323
- MISChttps://github.com/openresty/openresty/issues/930
- MISChttps://github.com/apache/apisix/issues/10320
- MISChttps://github.com/Azure/AKS/issues/3947
- MISChttps://github.com/Kong/kong/discussions/11741
- MISChttps://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
- MISChttps://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
- PATCHhttps://github.com/caddyserver/caddy/releases/tag/v2.7.5
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/13/4
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/13/9
- MISChttps://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/
- MAILING_LISThttps://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/
- MISChttps://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/10/msg00023.html
- MISChttps://security.netapp.com/advisory/ntap-20231016-0001/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/10/msg00024.html
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/18/4
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/18/8
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/19/6
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2023/10/20/8
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/10/msg00045.html
- VENDOR_ADVISORYhttps://www.debian.org/security/2023/dsa-5540
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/10/msg00047.html
- MISChttps://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/11/msg00001.html
- VENDOR_ADVISORYhttps://www.debian.org/security/2023/dsa-5549
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/
- VENDOR_ADVISORYhttps://www.debian.org/security/2023/dsa-5558
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2023/11/msg00012.html
- MISChttps://security.gentoo.org/glsa/202311-09
- VENDOR_ADVISORYhttps://www.debian.org/security/2023/dsa-5570
- MISChttps://security.netapp.com/advisory/ntap-20240426-0007/
- MISChttps://security.netapp.com/advisory/ntap-20240621-0006/
- MISChttps://security.netapp.com/advisory/ntap-20240621-0007/
- PATCHhttps://github.com/grpc/grpc/releases/tag/v1.59.2
- VENDOR_ADVISORYhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ
Updated 24m ago · 8 sources