CVE-2023-44487
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
8 articles
Published: 2023-10-10
EPSS Score
Source: FIRST.org · 2026-05-24
94.45%
probability
This CVE has a 94.45% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS v3.1
Source: VulnerabilityLookup (CIRCL)7.5
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
VulnerabilityLookup (CNA)The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Affected Products
n/a
n/a
Attack Intelligence
Exploits & PoC
bcdannyboy/CVE-2023-44487
Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487
242
secengjeff/rapidresetclient
Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)
75
Appsynergy-io/CVE-2023-44487
Proof of concept for DoS exploit
54
studiogangster/CVE-2023-44487
A python based exploit to test out rapid reset attack (CVE-2023-44487)
21
nxenon/cve-2023-44487
Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept
14
threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC
PoC CVE-2023-44487 — threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC
8
ndrscodes/http2-rst-stream-attacker
Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the
6
ReToCode/golang-CVE-2023-44487
PoC CVE-2023-44487 — ReToCode/golang-CVE-2023-44487
2
tpirate/cve-2023-44487-POC
poc for the rst dos attack discovered in 2023
2
aulauniversal/CVE-2023-44487
RapidResetClient
1
10 repos — triés par ⭐
Rechercher sur GitHub ↗
Signal Intelligence
Confidence
92%
EPSS
94.45%
CVSS v3.1
7.5
Mentions
8
Last Seen
Oct 17, 2023
CNA Information
CNA Assigner
mitre
Analyst Note
CVE-2023-44487 is the HTTP/2 Rapid Reset vulnerability explicitly documented as 'exploited in the wild in August through October 2023' per the official description. Exploitation occurred before and during the CVE publication date (2023-10-10), meeting the zero-day criterion of in-the-wild exploitation preceding/concurrent with patch availability.
Threat Actors 4
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
SNOWGLOBE
apt_group
Information theft and espionage
🇫🇷 FR
Red Dev 17
apt_group
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Triage Info
Decided atMar 05, 2026
Published DateOct 10, 2023