# Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487

DevFeed: [Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487](<https://devfeed.tech/articles/find-and-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487-7922.md>)

Original publisher: [Read original article](<https://snyk.io/blog/find-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487/>)

Author: Jamie Smith; Kriti Dogra; Anthony Larkin

Published: 2023-10-11T23:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [developer](<https://devfeed.tech/tags/developer.md>), [http](<https://devfeed.tech/tags/http.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

## AI overview

This article explains the HTTP/2 Rapid Reset vulnerability, tracked as CVE-2023-44487, which can enable large volumetric DDoS attacks against web servers implementing HTTP/2. It recommends mitigating exposure through infrastructure providers and CDNs, then upgrading affected packages and checking container images and open source ecosystems for remediated versions.

## Source excerpt

Learn how to find and fix the HTTP/2 rapid reset vulnerability (CVE-2023-44487) that has been designated a High severity vulnerability with a CVSS score of 7.5 (out of 10).