
CVE-2023-44487: HTTP/2 Rapid Reset DDoS Vulnerability
CVE-2023-44487 is the HTTP/2 Rapid Reset vulnerability, a flaw in HTTP/2's stream cancellation mechanism that allows a relatively small number of clients to generate HTTP/2 DDoS attacks far exceeding any previously observed scale. Google sustained a peak of 398 million requests per second; Cloudflare 201 million RPS; AWS observed similar records. The vulnerability affects all HTTP/2 server implementations. Coordinated disclosure on October 10, 2023 was accompanied by patches across major web server projects.
