The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
https://cert-portal.siemens.com/productcert/html/ssa-784301.html
https://cert-portal.siemens.com/productcert/html/ssa-341067.html
https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
https://www.securityweek.com/microsoft-ships-urgent-patch-for-exploited-windows-clfs-zero-day/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
https://www.theregister.com/2025/08/14/madeyoureset_http2_flaw_lets_attackers/
https://thehackernews.com/2025/08/new-http2-madeyoureset-vulnerability.html
https://kb.cert.org/vuls/id/767506
https://www.cisa.gov/news-events/ics-advisories/icsa-25-203-04
https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
https://cloud.google.com/support/bulletins/index#gcp-2025-023
https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08
https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-06
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-04
https://www.ibm.com/support/pages/node/7091444
https://www.zdnet.com/article/google-cloud-aws-and-cloudflare-report-largest-ddos-attacks-ever/
https://github.com/gunamata/container-cve-triage
https://github.com/Balckers/mcp-security-server
https://github.com/talmesilati/nginx-drop-in-rebuild
https://github.com/high-tech-r/quiet-cve
https://github.com/dasokkk/wapp2cve
https://github.com/CerberusMrXi/CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit
https://github.com/A-dev9077/Week-05-Computer-Networking-Fundamentals-Network-Configuration
https://github.com/cwayne18/vexscan
https://github.com/cwayne18/gomod-vex
https://github.com/stov3/fluescan
https://github.com/janderik/vuln-forge
https://github.com/manahylkhan/cveradar
https://github.com/kitsunetrail/stackwatch
https://github.com/kitsunetrail/kestrelynx
https://github.com/sumit760/cve-exploitability
https://github.com/rozetyp/vuln-intel-mcp
https://github.com/shreyash-dhawale/cve-advisory-publisher
https://github.com/cloudanimal/vuln-prioritization-toolkit
https://github.com/888irdy/vuln-analysis
https://github.com/offseq/threat-finder
https://github.com/omobolajiadeyan/vulngpt
https://github.com/kvsaurav/CVE-prioritization-
https://github.com/madhantr0/http2-security-lab
https://github.com/mrjoker-web/CVE-Research-Tool-v3.0
https://github.com/ayushghatkar8080/MadeYouReset_Tester
https://github.com/panaresh2007/osv-java-poc
https://github.com/BolajiEdu/cve-network-scanner
https://github.com/krish-achanta/vuln-validator
https://github.com/YasmeenAlgendy23/CVE_Intelligence_Assistant
https://github.com/aislabs-ai/cve-rank
https://github.com/hershate/CVE-Lookup-skill
https://github.com/BarAppTeam/nginx-cve-fix
https://github.com/pinialt/echo-assignment
https://github.com/Hirokiii/CVE-2023-44487
https://github.com/Manishadua/devsecops-daily
https://github.com/EJAtwood/mcp-vulnerability-server
https://github.com/taqi2508f-ui/SECURE-OPS
https://github.com/aarondutton-grc/nist-nvd-cve-to-cwe-mapper
https://github.com/phall-teleport/cve-reporter
https://github.com/unknownCyberEnthusiast/cve-cti
https://github.com/zaidxahmed-cyber/VulnAI
https://github.com/arunpushkar-dev/VulnPriority
https://github.com/wfarouk2023/MCP-CVE-server
https://github.com/narenndhra/cve_checker_simple
https://github.com/programmerq/cve-reporter
https://github.com/galletitaconpate/CVE-2023-44487
https://github.com/AswinMathew2004/cve-cli
https://github.com/Arshdeep030/CVE-Exploitation-Intelligence
https://github.com/oadeyan/vulngpt
https://github.com/mukul975/cve-mcp-server
https://github.com/RHEcosystemAppEng/exploitiq-mcp-server
https://github.com/user70616E6461/phantom-intel
https://github.com/Rishabh5649/CVE-Triage_Agent
https://github.com/dgiry/cve-enricher
https://github.com/kholcomb/threatbridge
https://github.com/Naim-ch/cve-enrichment-api
https://github.com/Naim-ch/CVE-Enrichment-API
https://github.com/marvang/vuln-variants
https://github.com/comandre-ex/cve-notifier
https://github.com/s3vtyq/vuln-scanner
https://github.com/JakobBartoschek/porthawk
https://github.com/hermestoola/bb-hunter-pro
https://github.com/apifyforge/cybersecurity-intelligence-mcp
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/cheenu1092-oss/netmcp
https://github.com/pantherica/CVE-Scanner
https://github.com/0xsir1s/cve-scanner
https://github.com/badchars/cve-mcp
https://github.com/gauravchaudhari02/pycve
https://github.com/gauravchaudhari02/PyCVE
https://github.com/dryfryce/phoenix-http2
https://github.com/dryfryce/phoenix-h2
https://github.com/dryfryce/http2-deep-research
https://github.com/Kalyan-Adhikari/CVE-Checker-Local
https://github.com/rawqubit/ai-cve-analyzer
https://github.com/michaelschecht/cve_lookup_tool
https://github.com/aishwaryeaah/cve-agent
https://github.com/Syn2Much/Slayer-L7
https://github.com/chasingimpact/vulnrag
https://github.com/xsss9188-DADHACKS/Exploit-Title-HTTP-2-2.0---Denial-Of-Service-DOS-
https://github.com/ctkqiang/QianKunQuan
https://github.com/8BitTacoSupreme/sbom_CVE_dash_demo
https://github.com/Syedomershah99/CVE-semantic-IEEE
https://github.com/brkothari/cve-analyzer
https://github.com/lhassa8/veridano-skill
https://github.com/YassBen-cyber/CVE-ANALYZER
https://github.com/jturini/PoC_Hunter
https://github.com/Kimiya00/security-threat-analyzer
https://github.com/Ja4mine/cve_management
https://github.com/moften/CVE-2025-8671-MadeYouReset-HTTP-2-DDoS
https://github.com/madhusudhan-in/CVE_2023_44487-Rapid_Reset
https://github.com/Arnabdaz/CVE-Search-MCP
https://github.com/boardwalkjoe/cve-security-check
https://github.com/ozanunal0/viper
https://github.com/mcdaqc/vulnerability-intelligence-diagrammatic-reasoning
https://github.com/moften/CVE-2022-41741-742-Nginx-Vulnerability-Scanner
https://github.com/zanks08/cve-2023-44487-demo
https://github.com/moften/CVE-2022-4174_CVE-2022-41742
https://github.com/aulauniversal/CVE-2023-44487
https://github.com/CyberSecAI/cve_info_refs_crawler
https://github.com/glkfc/CVE_Reproduce
https://github.com/knabben/dos-poc
https://github.com/terrorist/HTTP-2-Rapid-Reset-Client
https://github.com/nxenon/cve-2023-44487
https://github.com/studiogangster/CVE-2023-44487
https://github.com/secengjeff/rapidresetclient
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
https://github.com/oscerd/nice-cve-poc
https://github.com/pabloec20/rapidreset
https://github.com/ByteHackr/CVE-2023-44487
Published: 2023-10-10
Updated: 2026-08-11
Named Vulnerability: Rapid ResetNamed Vulnerability: HTTP/2 Rapid Reset AttackNamed Vulnerability: HTTP/2 Rapid ResetKnown Exploited Vulnerability (KEV)
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C
Severity: High
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity: High
Base Score: 6.9
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.99999