HTTP/Who? CVE-2023-44487
ID: a65dc212-1475-5721-8f5d-f1d26501a3fe
STIX ID: report--a65dc212-1475-5721-8f5d-f1d26501a3fe
Feed Name: Censys Blog
Date Published: 2023-10-12
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
Censys reports on the HTTP/2 "Rapid Reset" denial-of-service technique disclosed by Google and Cloudflare, where attackers rapidly open and cancel HTTP/2 streams to reset per-client request counters and overwhelm proxied backend services; Censys notes ~556M hosts able to run HTTP/2, no definitive workaround at the time, and recommends temporary mitigation (disable HTTP/2 on frontends) plus DDoS protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
