{"id":"DEBIAN-CVE-2023-44487","details":"The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.","modified":"2026-09-15T09:02:25.676282215Z","published":"2023-10-10T14:15:10.883Z","upstream":["CVE-2023-44487"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-44487"}],"affected":[{"package":{"name":"dnsdist","ecosystem":"Debian:12","purl":"pkg:deb/debian/dnsdist?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.3-2","1.8.0-1","1.8.1-1","1.8.2-1","1.8.2-2","1.8.2-3","1.8.3-1","1.8.3-2","1.8.3-3","1.9.10-1","1.9.3-1","1.9.4-1","1.9.5-1","1.9.6-1","1.9.8-1","1.9.9-1","2.0.0-1","2.0.0-2","2.0.0-3","2.0.0-4","2.0.0-5","2.0.0-6","2.0.0~rc1-1","2.0.0~rc1-2","2.0.0~rc2-1","2.0.1-1","2.0.2-1","2.0.3-1","2.0.4-1","2.0.5-1","2.0.5-2","2.0.5-3","2.0.6-1","2.1.0-1","2.1.0-2","2.1.1-1","2.1.2-1"],"ecosystem_specific":{"urgency":"end-of-life"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"dnsdist","ecosystem":"Debian:13","purl":"pkg:deb/debian/dnsdist?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.2-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"dnsdist","ecosystem":"Debian:14","purl":"pkg:deb/debian/dnsdist?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.2-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"grpc","ecosystem":"Debian:12","purl":"pkg:deb/debian/grpc?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.51.1-3","1.51.1-4","1.51.1-4.1","1.51.1-4.1~exp1","1.51.1-5","1.51.1-6","1.51.1-7","1.51.1-8","1.51.1-9","1.59.5-1","1.82.0-1","1.83.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"grpc","ecosystem":"Debian:13","purl":"pkg:deb/debian/grpc?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.51.1-6","1.51.1-7","1.51.1-8","1.51.1-9","1.59.5-1","1.82.0-1","1.83.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"grpc","ecosystem":"Debian:14","purl":"pkg:deb/debian/grpc?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.51.1-6","1.51.1-7","1.51.1-8","1.51.1-9","1.59.5-1","1.82.0-1","1.83.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"h2o","ecosystem":"Debian:12","purl":"pkg:deb/debian/h2o?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.5+dfsg2-10","2.2.5+dfsg2-11","2.2.5+dfsg2-7","2.2.5+dfsg2-8","2.2.5+dfsg2-8.1","2.2.5+dfsg2-8.1~exp1","2.2.5+dfsg2-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"haproxy","ecosystem":"Debian:12","purl":"pkg:deb/debian/haproxy?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"haproxy","ecosystem":"Debian:13","purl":"pkg:deb/debian/haproxy?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"haproxy","ecosystem":"Debian:14","purl":"pkg:deb/debian/haproxy?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"jetty9","ecosystem":"Debian:12","purl":"pkg:deb/debian/jetty9?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4.50-4+deb12u2"}]}],"versions":["9.4.50-4","9.4.50-4+deb12u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"jetty9","ecosystem":"Debian:13","purl":"pkg:deb/debian/jetty9?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4.53-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"jetty9","ecosystem":"Debian:14","purl":"pkg:deb/debian/jetty9?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4.53-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"netty","ecosystem":"Debian:12","purl":"pkg:deb/debian/netty?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.48-7+deb12u1"}]}],"versions":["1:4.1.48-7"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"netty","ecosystem":"Debian:13","purl":"pkg:deb/debian/netty?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.48-8"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"netty","ecosystem":"Debian:14","purl":"pkg:deb/debian/netty?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.48-8"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"nghttp2","ecosystem":"Debian:12","purl":"pkg:deb/debian/nghttp2?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.52.0-1+deb12u1"}]}],"versions":["1.52.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"nghttp2","ecosystem":"Debian:13","purl":"pkg:deb/debian/nghttp2?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.57.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"nghttp2","ecosystem":"Debian:14","purl":"pkg:deb/debian/nghttp2?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.57.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"nginx","ecosystem":"Debian:12","purl":"pkg:deb/debian/nginx?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.22.1-9","1.22.1-9+deb12u1","1.22.1-9+deb12u2","1.22.1-9+deb12u3","1.22.1-9+deb12u4","1.22.1-9+deb12u5","1.22.1-9+deb12u6","1.22.1-9+deb12u7","1.22.1-9+deb12u8","1.22.1-9+deb12u9","1.24.0-1","1.24.0-1~exp1","1.24.0-2","1.26.0-1","1.26.0-1~exp1","1.26.0-2","1.26.0-3","1.26.2-1","1.26.3-1","1.26.3-2","1.26.3-3","1.28.0-1","1.28.0-2","1.28.0-3","1.28.0-4","1.28.0-5","1.28.0-6","1.28.1-1","1.28.1-2","1.28.1-3","1.28.2-1","1.28.2-2","1.28.2-3","1.28.2-4","1.28.3-1","1.28.3-2","1.30.0-1","1.30.0-2","1.30.0-3","1.30.0-4","1.30.1-1","1.30.1-2","1.30.1-3","1.30.1-4","1.30.1-5","1.30.1-6","1.30.1-7","1.30.4-1","1.30.4-2","1.30.4-3","1.30.4-4","1.30.4-5","1.30.4-6"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"nginx","ecosystem":"Debian:13","purl":"pkg:deb/debian/nginx?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.24.0-2"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"nginx","ecosystem":"Debian:14","purl":"pkg:deb/debian/nginx?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.24.0-2"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"tomcat10","ecosystem":"Debian:12","purl":"pkg:deb/debian/tomcat10?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.6-1+deb12u1"}]}],"versions":["10.1.6-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"tomcat10","ecosystem":"Debian:13","purl":"pkg:deb/debian/tomcat10?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"tomcat10","ecosystem":"Debian:14","purl":"pkg:deb/debian/tomcat10?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"tomcat9","ecosystem":"Debian:12","purl":"pkg:deb/debian/tomcat9?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.70-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"tomcat9","ecosystem":"Debian:13","purl":"pkg:deb/debian/tomcat9?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.70-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"tomcat9","ecosystem":"Debian:14","purl":"pkg:deb/debian/tomcat9?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.70-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"trafficserver","ecosystem":"Debian:12","purl":"pkg:deb/debian/trafficserver?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.3+ds-1+deb12u1"}]}],"versions":["9.2.0+ds-2","9.2.0+ds-2+deb12u1","9.2.1+ds-1","9.2.2+ds-1","9.2.3+ds-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"varnish","ecosystem":"Debian:12","purl":"pkg:deb/debian/varnish?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.1.1-1.1","7.1.1-1.1+deb12u1","7.1.1-1.2","7.1.1-2+deb12u1","7.5.0-1","7.5.0-2","7.5.0-3","7.6.0-1","7.6.0-2","7.6.1-1","7.6.1-2","7.7.0-1","7.7.0-2","7.7.0-3","7.7.1-1","7.7.2-1","7.7.2-2","7.7.3-1","7.7.3-2","7.7.3-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}},{"package":{"name":"varnish","ecosystem":"Debian:13","purl":"pkg:deb/debian/varnish?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-44487.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}