Critical Alert 2 Active Exploits Detected Today

CVE-2026-102490 — Zammad GmbH Zammad Improper Privilege Management Vulnerability →
CVE-2026-102489 — Zammad GmbH Zammad Session Fixation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2023-44487NVD

Vulnerability Summary

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Severity Level
HIGH(7.5)
Published Date
Oct 10, 2023
Last Modified
Aug 11, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
100.00%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Siemens Simatic S7-1500 Cpu 1518f-4 Pn\/dp Mfp Firmware >= 3.1.5
  • Siemens Sinec Ins < 1.0
  • Siemens Sinec Ins
  • Siemens Sinec Nms < 3.0
  • Siemens St7 Scadaconnect < 1.1
  • Siemens Ruggedcom Ape1808 Firmware
  • Siemens Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp Firmware >= 3.1.5
  • Siemens Siplus S7-1500 Cpu 1518-4 Pn\/dp Mfp Firmware >= 3.1.5
  • Ietf Http
  • Nghttp2 Nghttp2 < 1.57.0
  • Netty Netty < 4.1.100
  • Envoyproxy Envoy
  • Eclipse Jetty < 9.4.53
  • Eclipse Jetty >= 10.0.0 and < 10.0.17
  • Eclipse Jetty >= 11.0.0 and < 11.0.17
  • Eclipse Jetty >= 12.0.0 and < 12.0.2
  • Caddyserver Caddy < 2.7.5
  • Golang Go < 1.20.10
  • Golang Go >= 1.21.0 and < 1.21.3
  • Golang Http2 < 0.17.0
  • Golang Networking < 0.17.0
  • F5 Big-ip Access Policy Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Access Policy Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Access Policy Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Access Policy Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Access Policy Manager
  • F5 Big-ip Advanced Firewall Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Advanced Firewall Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Advanced Firewall Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Advanced Firewall Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Advanced Firewall Manager
  • F5 Big-ip Advanced Web Application Firewall >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Advanced Web Application Firewall >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Advanced Web Application Firewall >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Advanced Web Application Firewall >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Advanced Web Application Firewall
  • F5 Big-ip Analytics >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Analytics >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Analytics >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Analytics >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Analytics
  • F5 Big-ip Application Acceleration Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Application Acceleration Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Application Acceleration Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Application Acceleration Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Application Acceleration Manager
  • F5 Big-ip Application Security Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Application Security Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Application Security Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Application Security Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Application Security Manager
  • F5 Big-ip Application Visibility And Reporting >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Application Visibility And Reporting >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Application Visibility And Reporting >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Application Visibility And Reporting >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Application Visibility And Reporting
  • F5 Big-ip Carrier-grade Nat >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Carrier-grade Nat >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Carrier-grade Nat >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Carrier-grade Nat >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Carrier-grade Nat
  • F5 Big-ip Ddos Hybrid Defender >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Ddos Hybrid Defender >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Ddos Hybrid Defender >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Ddos Hybrid Defender >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Ddos Hybrid Defender
  • F5 Big-ip Domain Name System >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Domain Name System >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Domain Name System >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Domain Name System >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Domain Name System
  • F5 Big-ip Fraud Protection Service >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Fraud Protection Service >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Fraud Protection Service >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Fraud Protection Service >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Fraud Protection Service
  • F5 Big-ip Global Traffic Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Global Traffic Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Global Traffic Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Global Traffic Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Global Traffic Manager
  • F5 Big-ip Link Controller >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Link Controller >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Link Controller >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Link Controller >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Link Controller
  • F5 Big-ip Local Traffic Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Local Traffic Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Local Traffic Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Local Traffic Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Local Traffic Manager
  • F5 Big-ip Next
  • F5 Big-ip Next Service Proxy For Kubernetes >= 1.5.0 and <= 1.8.2
  • F5 Big-ip Policy Enforcement Manager >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Policy Enforcement Manager >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Policy Enforcement Manager >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Policy Enforcement Manager >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Policy Enforcement Manager
  • F5 Big-ip Ssl Orchestrator >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Ssl Orchestrator >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Ssl Orchestrator >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Ssl Orchestrator >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Ssl Orchestrator
  • F5 Big-ip Webaccelerator >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Webaccelerator >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Webaccelerator >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Webaccelerator >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Webaccelerator
  • F5 Big-ip Websafe >= 13.1.0 and <= 13.1.5
  • F5 Big-ip Websafe >= 14.1.0 and <= 14.1.5
  • F5 Big-ip Websafe >= 15.1.0 and <= 15.1.10
  • F5 Big-ip Websafe >= 16.1.0 and <= 16.1.4
  • F5 Big-ip Websafe
  • F5 Nginx >= 1.9.5 and <= 1.25.2
  • F5 Nginx Ingress Controller >= 2.0.0 and <= 2.4.2
  • F5 Nginx Ingress Controller >= 3.0.0 and <= 3.3.0
  • F5 Nginx Plus >= r25 and < r29
  • F5 Nginx Plus
  • Apache Tomcat >= 8.5.0 and <= 8.5.93
  • Apache Tomcat >= 9.0.0 and <= 9.0.80
  • Apache Tomcat >= 10.1.0 and <= 10.1.13
  • Apache Tomcat
  • Apple Swiftnio Http\/2 < 1.28.0
  • Grpc Grpc < 1.56.3
  • Grpc Grpc <= 1.59.2
  • Grpc Grpc >= 1.58.0 and < 1.58.3
  • Grpc Grpc
  • Microsoft .net >= 6.0.0 and < 6.0.23
  • Microsoft .net >= 7.0.0 and < 7.0.12
  • Microsoft Asp.net Core >= 6.0.0 and < 6.0.23
  • Microsoft Asp.net Core >= 7.0.0 and < 7.0.12
  • Microsoft Azure Kubernetes Service < 2023-10-08
  • Microsoft Visual Studio 2022 >= 17.0 and < 17.2.20
  • Microsoft Visual Studio 2022 >= 17.4 and < 17.4.12
  • Microsoft Visual Studio 2022 >= 17.6 and < 17.6.8
  • Microsoft Visual Studio 2022 >= 17.7 and < 17.7.5
  • Microsoft Windows 10 1607 < 10.0.14393.6351
  • Microsoft Windows 10 1809 < 10.0.17763.4974
  • Microsoft Windows 10 21h2 < 10.0.19044.3570
  • Microsoft Windows 10 22h2 < 10.0.19045.3570
  • Microsoft Windows 11 21h2 < 10.0.22000.2538
  • Microsoft Windows 11 22h2 < 10.0.22621.2428
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022
  • Nodejs Node.js >= 18.0.0 and < 18.18.2
  • Nodejs Node.js >= 20.0.0 and < 20.8.1
  • Microsoft Cbl-mariner < 2023-10-11
  • Dena H2o < 2023-10-10
  • Facebook Proxygen < 2023.10.16.00
  • Apache Apisix < 3.6.1
  • Apache Traffic Server >= 8.0.0 and < 8.1.9
  • Apache Traffic Server >= 9.0.0 and < 9.2.3
  • Amazon Opensearch Data Prepper < 2.5.0
  • Debian Debian Linux
  • Kazu-yamamoto Http2 < 4.2.2
  • Istio Istio < 1.17.6
  • Istio Istio >= 1.18.0 and < 1.18.3
  • Istio Istio >= 1.19.0 and < 1.19.1
  • Varnish Cache Project Varnish Cache < 2023-10-10
  • Traefik Traefik < 2.10.5
  • Traefik Traefik
  • Projectcontour Contour < 2023-10-11
  • Linkerd Linkerd >= 2.12.0 and <= 2.12.5
  • Linkerd Linkerd
  • Linecorp Armeria < 1.26.0
  • Redhat 3scale Api Management Platform
  • Redhat Advanced Cluster Management For Kubernetes
  • Redhat Advanced Cluster Security
  • Redhat Ansible Automation Platform
  • Redhat Build Of Optaplanner
  • Redhat Build Of Quarkus
  • Redhat Ceph Storage
  • Redhat Cert-manager Operator For Red Hat Openshift
  • Redhat Certification For Red Hat Enterprise Linux
  • Redhat Cost Management
  • Redhat Cryostat
  • Redhat Decision Manager
  • Redhat Fence Agents Remediation Operator
  • Redhat Integration Camel For Spring Boot
  • Redhat Integration Camel K
  • Redhat Integration Service Registry
  • Redhat Jboss A-mq
  • Redhat Jboss A-mq Streams
  • Redhat Jboss Core Services
  • Redhat Jboss Data Grid
  • Redhat Jboss Enterprise Application Platform
  • Redhat Jboss Fuse
  • Redhat Logging Subsystem For Red Hat Openshift
  • Redhat Machine Deletion Remediation Operator
  • Redhat Migration Toolkit For Applications
  • Redhat Migration Toolkit For Containers
  • Redhat Migration Toolkit For Virtualization
  • Redhat Network Observability Operator
  • Redhat Node Healthcheck Operator
  • Redhat Node Maintenance Operator
  • Redhat Openshift
  • Redhat Openshift Api For Data Protection
  • Redhat Openshift Container Platform
  • Redhat Openshift Container Platform Assisted Installer
  • Redhat Openshift Data Science
  • Redhat Openshift Dev Spaces
  • Redhat Openshift Developer Tools And Services
  • Redhat Openshift Distributed Tracing
  • Redhat Openshift Gitops
  • Redhat Openshift Pipelines
  • Redhat Openshift Sandboxed Containers
  • Redhat Openshift Secondary Scheduler Operator
  • Redhat Openshift Serverless
  • Redhat Openshift Service Mesh
  • Redhat Openshift Virtualization
  • Redhat Openstack Platform
  • Redhat Process Automation
  • Redhat Quay
  • Redhat Run Once Duration Override Operator
  • Redhat Satellite
  • Redhat Self Node Remediation Operator
  • Redhat Service Interconnect
  • Redhat Single Sign-on
  • Redhat Support For Spring Boot
  • Redhat Web Terminal
  • Redhat Enterprise Linux
  • Redhat Service Telemetry Framework
  • Fedoraproject Fedora
  • Netapp Astra Control Center
  • Netapp Oncommand Insight
  • Akka Http Server < 10.5.3
  • Konghq Kong Gateway < 3.4.2
  • Jenkins Jenkins <= 2.414.2
  • Jenkins Jenkins <= 2.427
  • Apache Solr < 9.4.0
  • Openresty Openresty < 1.21.4.3
  • Cisco Business Process Automation < 3.2.003.009
  • Cisco Connected Mobile Experiences < 11.1
  • Cisco Crosswork Data Gateway < 4.1.3
  • Cisco Crosswork Data Gateway >= 5.0.0 and < 5.0.2
  • Cisco Crosswork Situation Manager
  • Cisco Crosswork Zero Touch Provisioning < 6.0.0
  • Cisco Data Center Network Manager
  • Cisco Enterprise Chat And Email
  • Cisco Expressway < x14.3.3
  • Cisco Iot Field Network Director < 4.11.0
  • Cisco Prime Access Registrar < 9.3.3
  • Cisco Prime Cable Provisioning < 7.2.1
  • Cisco Prime Infrastructure < 3.10.4
  • Cisco Prime Network Registrar < 11.2
  • Cisco Secure Dynamic Attributes Connector < 2.2.0
  • Cisco Secure Firewall Threat Defense < 7.4.2
  • Cisco Secure Malware Analytics < 2.19.2
  • Cisco Telepresence Video Communication Server < x14.3.3
  • Cisco Ultra Cloud Core - Policy Control Function < 2024.01.0
  • Cisco Ultra Cloud Core - Policy Control Function
  • Cisco Ultra Cloud Core - Serving Gateway Function < 2024.02.0
  • Cisco Ultra Cloud Core - Session Management Function < 2024.02.0
  • Cisco Unified Attendant Console Advanced
  • Cisco Unified Contact Center Domain Manager
  • Cisco Unified Contact Center Enterprise
  • Cisco Unified Contact Center Enterprise - Live Data Server < 12.6.2
  • Cisco Unified Contact Center Management Portal
  • Cisco Fog Director < 1.22
  • Cisco Ios Xe < 17.15.1
  • Cisco Ios Xr < 7.11.2
  • Cisco Secure Web Appliance Firmware < 15.1.0
  • Cisco Nx-os < 10.2\(7\)
  • Cisco Nx-os >= 10.3\(1\) and < 10.3\(5\)
  • Cisco Nx-os >= 10.4\(1\) and < 10.4\(2\)
Patched Versions
  • Siemens Sinec Ins 1.0
  • Siemens Sinec Nms 3.0
  • Siemens St7 Scadaconnect 1.1
  • Nghttp2 Nghttp2 1.57.0
  • Netty Netty 4.1.100
  • Eclipse Jetty 9.4.53
  • Eclipse Jetty 10.0.17
  • Eclipse Jetty 11.0.17
  • Eclipse Jetty 12.0.2
  • Caddyserver Caddy 2.7.5
  • Golang Go 1.20.10
  • Golang Go 1.21.3
  • Golang Http2 0.17.0
  • Golang Networking 0.17.0
  • F5 Nginx Plus r29
  • Apple Swiftnio Http\/2 1.28.0
  • Grpc Grpc 1.56.3
  • Grpc Grpc 1.58.3
  • Microsoft .net 6.0.23
  • Microsoft .net 7.0.12
  • Microsoft Asp.net Core 6.0.23
  • Microsoft Asp.net Core 7.0.12
  • Microsoft Azure Kubernetes Service 2023-10-08
  • Microsoft Visual Studio 2022 17.2.20
  • Microsoft Visual Studio 2022 17.4.12
  • Microsoft Visual Studio 2022 17.6.8
  • Microsoft Visual Studio 2022 17.7.5
  • Microsoft Windows 10 1607 10.0.14393.6351
  • Microsoft Windows 10 1809 10.0.17763.4974
  • Microsoft Windows 10 21h2 10.0.19044.3570
  • Microsoft Windows 10 22h2 10.0.19045.3570
  • Microsoft Windows 11 21h2 10.0.22000.2538
  • Microsoft Windows 11 22h2 10.0.22621.2428
  • Nodejs Node.js 18.18.2
  • Nodejs Node.js 20.8.1
  • Microsoft Cbl-mariner 2023-10-11
  • Dena H2o 2023-10-10
  • Facebook Proxygen 2023.10.16.00
  • Apache Apisix 3.6.1
  • Apache Traffic Server 8.1.9
  • Apache Traffic Server 9.2.3
  • Amazon Opensearch Data Prepper 2.5.0
  • Kazu-yamamoto Http2 4.2.2
  • Istio Istio 1.17.6
  • Istio Istio 1.18.3
  • Istio Istio 1.19.1
  • Varnish Cache Project Varnish Cache 2023-10-10
  • Traefik Traefik 2.10.5
  • Projectcontour Contour 2023-10-11
  • Linecorp Armeria 1.26.0
  • Akka Http Server 10.5.3
  • Konghq Kong Gateway 3.4.2
  • Apache Solr 9.4.0
  • Openresty Openresty 1.21.4.3
  • Cisco Business Process Automation 3.2.003.009
  • Cisco Connected Mobile Experiences 11.1
  • Cisco Crosswork Data Gateway 4.1.3
  • Cisco Crosswork Data Gateway 5.0.2
  • Cisco Crosswork Zero Touch Provisioning 6.0.0
  • Cisco Expressway x14.3.3
  • Cisco Iot Field Network Director 4.11.0
  • Cisco Prime Access Registrar 9.3.3
  • Cisco Prime Cable Provisioning 7.2.1
  • Cisco Prime Infrastructure 3.10.4
  • Cisco Prime Network Registrar 11.2
  • Cisco Secure Dynamic Attributes Connector 2.2.0
  • Cisco Secure Firewall Threat Defense 7.4.2
  • Cisco Secure Malware Analytics 2.19.2
  • Cisco Telepresence Video Communication Server x14.3.3
  • Cisco Ultra Cloud Core - Policy Control Function 2024.01.0
  • Cisco Ultra Cloud Core - Serving Gateway Function 2024.02.0
  • Cisco Ultra Cloud Core - Session Management Function 2024.02.0
  • Cisco Unified Contact Center Enterprise - Live Data Server 12.6.2
  • Cisco Fog Director 1.22
  • Cisco Ios Xe 17.15.1
  • Cisco Ios Xr 7.11.2
  • Cisco Secure Web Appliance Firmware 15.1.0
  • Cisco Nx-os 10.2\(7\)
  • Cisco Nx-os 10.3\(5\)
  • Cisco Nx-os 10.4\(2\)
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.

External References