CVE-2023-44487

KEV
Published: Ott 10, 2023 Last Modified: Nov 07, 2025
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,9443
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
All platforms may be affected
View CWE Details
Exploit

HTTP/2 2.0 - Denial Of Service (DOS)

HTTP/2 2.0 - Denial Of Service (DOS)

View Exploit Code →
Application

Big-Ip Local Traffic Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows Server 2016 by Microsoft

cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Varnish Cache by Varnish Cache Project

Version Range Affected
To 2023-10-10 (exclusive)
cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Firewall Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Web Application Firewall by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

Version Range Affected
From 10.1.0 (inclusive)
To 10.1.13 (inclusive)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Debian Linux by Debian

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Swiftnio Http\/2 by Apple

Version Range Affected
To 1.28.0 (exclusive)
cpe:2.3:a:apple:swiftnio_http\/2:*:*:*:*:*:swift:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Domain Name System by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 11.0.0 (inclusive)
To 11.0.17 (exclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Nx-Os by Cisco

Version Range Affected
From 10.3\(1\) (inclusive)
To 10.3\(5\) (exclusive)
cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Global Traffic Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Link Controller by F5

cpe:2.3:a:f5:big-ip_link_controller:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Access Policy Manager by F5

cpe:2.3:a:f5:big-ip_access_policy_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 11 21H2 by Microsoft

Version Range Affected
To 10.0.22000.2538 (exclusive)
cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Carrier-Grade Nat by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nginx by F5

Version Range Affected
From 1.9.5 (inclusive)
To 1.25.2 (inclusive)
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Asp.Net Core by Microsoft

Version Range Affected
From 7.0.0 (inclusive)
To 7.0.12 (exclusive)
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Service Interconnect by Redhat

cpe:2.3:a:redhat:service_interconnect:1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Visual Studio 2022 by Microsoft

Version Range Affected
From 17.0 (inclusive)
To 17.2.20 (exclusive)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Web Application Firewall by F5

cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Security Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ios Xr by Cisco

Version Range Affected
To 7.11.2 (exclusive)
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 10 22H2 by Microsoft

Version Range Affected
To 10.0.19045.3570 (exclusive)
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Webaccelerator by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ultra Cloud Core - Serving Gateway Function by Cisco

Version Range Affected
To 2024.02.0 (exclusive)
cpe:2.3:a:cisco:ultra_cloud_core_-_serving_gateway_function:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Firewall Manager by F5

cpe:2.3:a:f5:big-ip_advanced_firewall_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Envoy by Envoyproxy

cpe:2.3:a:envoyproxy:envoy:1.24.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Prime Network Registrar by Cisco

Version Range Affected
To 11.2 (exclusive)
cpe:2.3:a:cisco:prime_network_registrar:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Asp.Net Core by Microsoft

Version Range Affected
From 6.0.0 (inclusive)
To 6.0.23 (exclusive)
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Build Of Optaplanner by Redhat

cpe:2.3:a:redhat:build_of_optaplanner:8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Analytics by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Process Automation by Redhat

cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Traefik by Traefik

cpe:2.3:a:traefik:traefik:3.0.0:beta3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Visual Studio 2022 by Microsoft

Version Range Affected
From 17.7 (inclusive)
To 17.7.5 (exclusive)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Carrier-Grade Nat by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Acceleration Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openresty by Openresty

Version Range Affected
To 1.21.4.3 (exclusive)
cpe:2.3:a:openresty:openresty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Linkerd by Linkerd

cpe:2.3:a:linkerd:linkerd:2.13.1:*:*:*:stable:kubernetes:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Istio by Istio

Version Range Affected
To 1.17.6 (exclusive)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Fog Director by Cisco

Version Range Affected
To 1.22 (exclusive)
cpe:2.3:o:cisco:fog_director:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Link Controller by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Machine Deletion Remediation Operator by Redhat

cpe:2.3:a:redhat:machine_deletion_remediation_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Secure Dynamic Attributes Connector by Cisco

Version Range Affected
To 2.2.0 (exclusive)
cpe:2.3:a:cisco:secure_dynamic_attributes_connector:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Webaccelerator by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux by Redhat

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ddos Hybrid Defender by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Crosswork Situation Manager by Cisco

cpe:2.3:a:cisco:crosswork_situation_manager:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Go by Golang

Version Range Affected
To 1.20.10 (exclusive)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nginx Ingress Controller by F5

Version Range Affected
From 2.0.0 (inclusive)
To 2.4.2 (inclusive)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Network Observability Operator by Redhat

cpe:2.3:a:redhat:network_observability_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certification For Red Hat Enterprise Linux by Redhat

cpe:2.3:a:redhat:certification_for_red_hat_enterprise_linux:8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Linkerd by Linkerd

cpe:2.3:a:linkerd:linkerd:2.13.0:*:*:*:stable:kubernetes:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Telepresence Video Communication Server by Cisco

Version Range Affected
To x14.3.3 (exclusive)
cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Traefik by Traefik

cpe:2.3:a:traefik:traefik:3.0.0:beta1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Policy Enforcement Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Webaccelerator by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Global Traffic Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Access Policy Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Azure Kubernetes Service by Microsoft

Version Range Affected
To 2023-10-08 (exclusive)
cpe:2.3:a:microsoft:azure_kubernetes_service:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Migration Toolkit For Applications by Redhat

cpe:2.3:a:redhat:migration_toolkit_for_applications:6.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Webaccelerator by F5

cpe:2.3:a:f5:big-ip_webaccelerator:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Crosswork Data Gateway by Cisco

Version Range Affected
From 5.0.0 (inclusive)
To 5.0.2 (exclusive)
cpe:2.3:a:cisco:crosswork_data_gateway:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Next Service Proxy For Kubernetes by F5

Version Range Affected
From 1.5.0 (inclusive)
To 1.8.2 (inclusive)
cpe:2.3:a:f5:big-ip_next_service_proxy_for_kubernetes:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Local Traffic Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

.Net by Microsoft

Version Range Affected
From 6.0.0 (inclusive)
To 6.0.23 (exclusive)
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Pipelines by Redhat

cpe:2.3:a:redhat:openshift_pipelines:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Linkerd by Linkerd

cpe:2.3:a:linkerd:linkerd:2.14.0:*:*:*:stable:kubernetes:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Local Traffic Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Debian Linux by Debian

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ultra Cloud Core - Policy Control Function by Cisco

cpe:2.3:a:cisco:ultra_cloud_core_-_policy_control_function:2024.01.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone6:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Advanced Cluster Management For Kubernetes by Redhat

cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openstack Platform by Redhat

cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Visibility And Reporting by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Carrier-Grade Nat by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 10 1607 by Microsoft

Version Range Affected
To 10.0.14393.6351 (exclusive)
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Migration Toolkit For Containers by Redhat

cpe:2.3:a:redhat:migration_toolkit_for_containers:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ceph Storage by Redhat

cpe:2.3:a:redhat:ceph_storage:5.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Traffic Server by Apache

Version Range Affected
From 9.0.0 (inclusive)
To 9.2.3 (exclusive)
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Prime Cable Provisioning by Cisco

Version Range Affected
To 7.2.1 (exclusive)
cpe:2.3:a:cisco:prime_cable_provisioning:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Websafe by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Secure Web Appliance Firmware by Cisco

Version Range Affected
To 15.1.0 (exclusive)
cpe:2.3:o:cisco:secure_web_appliance_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jenkins by Jenkins

Version Range Affected
To 2.427 (inclusive)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Local Traffic Manager by F5

cpe:2.3:a:f5:big-ip_local_traffic_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone10:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Websafe by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss A-Mq Streams by Redhat

cpe:2.3:a:redhat:jboss_a-mq_streams:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nginx Plus by F5

cpe:2.3:a:f5:nginx_plus:r29:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Analytics by F5

cpe:2.3:a:f5:big-ip_analytics:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Web Application Firewall by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ssl Orchestrator by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Acceleration Manager by F5

cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Prime Infrastructure by Cisco

Version Range Affected
To 3.10.4 (exclusive)
cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Istio by Istio

Version Range Affected
From 1.19.0 (inclusive)
To 1.19.1 (exclusive)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Global Traffic Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Container Platform Assisted Installer by Redhat

cpe:2.3:a:redhat:openshift_container_platform_assisted_installer:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Security Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Grpc by Grpc

Version Range Affected
To 1.56.3 (exclusive)
cpe:2.3:a:grpc:grpc:*:*:*:*:*:go:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone7:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Go by Golang

Version Range Affected
From 1.21.0 (inclusive)
To 1.21.3 (exclusive)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Caddy by Caddyserver

Version Range Affected
To 2.7.5 (exclusive)
cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift by Redhat

cpe:2.3:a:redhat:openshift:-:*:*:*:*:aws:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

3Scale Api Management Platform by Redhat

cpe:2.3:a:redhat:3scale_api_management_platform:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Expressway by Cisco

Version Range Affected
To x14.3.3 (exclusive)
cpe:2.3:a:cisco:expressway:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ssl Orchestrator by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Firewall Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Policy Enforcement Manager by F5

cpe:2.3:a:f5:big-ip_policy_enforcement_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ios Xe by Cisco

Version Range Affected
To 17.15.1 (exclusive)
cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Visibility And Reporting by F5

cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Decision Manager by Redhat

cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Node.Js by Nodejs

Version Range Affected
From 20.0.0 (inclusive)
To 20.8.1 (exclusive)
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nginx Ingress Controller by F5

Version Range Affected
From 3.0.0 (inclusive)
To 3.3.0 (inclusive)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Envoy by Envoyproxy

cpe:2.3:a:envoyproxy:envoy:1.26.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Envoy by Envoyproxy

cpe:2.3:a:envoyproxy:envoy:1.25.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Cert-Manager Operator For Red Hat Openshift by Redhat

cpe:2.3:a:redhat:cert-manager_operator_for_red_hat_openshift:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Self Node Remediation Operator by Redhat

cpe:2.3:a:redhat:self_node_remediation_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Opensearch Data Prepper by Amazon

Version Range Affected
To 2.5.0 (exclusive)
cpe:2.3:a:amazon:opensearch_data_prepper:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Prime Access Registrar by Cisco

Version Range Affected
To 9.3.3 (exclusive)
cpe:2.3:a:cisco:prime_access_registrar:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Enterprise Application Platform by Redhat

cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Access Policy Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Serverless by Redhat

cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Access Policy Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Integration Camel For Spring Boot by Redhat

cpe:2.3:a:redhat:integration_camel_for_spring_boot:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Data Center Network Manager by Cisco

cpe:2.3:a:cisco:data_center_network_manager:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Local Traffic Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ddos Hybrid Defender by F5

cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Analytics by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ansible Automation Platform by Redhat

cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Carrier-Grade Nat by F5

cpe:2.3:a:f5:big-ip_carrier-grade_nat:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Api For Data Protection by Redhat

cpe:2.3:a:redhat:openshift_api_for_data_protection:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Acceleration Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux by Redhat

cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Networking by Golang

Version Range Affected
To 0.17.0 (exclusive)
cpe:2.3:a:golang:networking:*:*:*:*:*:go:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ddos Hybrid Defender by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows Server 2022 by Microsoft

cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Policy Enforcement Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Global Traffic Manager by F5

cpe:2.3:a:f5:big-ip_global_traffic_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firepower Threat Defense by Cisco

Version Range Affected
To 7.4.2 (exclusive)
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Satellite by Redhat

cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Domain Name System by F5

cpe:2.3:a:f5:big-ip_domain_name_system:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Linkerd by Linkerd

Version Range Affected
From 2.12.0 (inclusive)
To 2.12.5 (inclusive)
cpe:2.3:a:linkerd:linkerd:*:*:*:*:stable:kubernetes:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Security Manager by F5

cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Firewall Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Visibility And Reporting by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ssl Orchestrator by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Websafe by F5

cpe:2.3:a:f5:big-ip_websafe:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Node Healthcheck Operator by Redhat

cpe:2.3:a:redhat:node_healthcheck_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

.Net by Microsoft

Version Range Affected
From 7.0.0 (inclusive)
To 7.0.12 (exclusive)
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Solr by Apache

Version Range Affected
To 9.4.0 (exclusive)
cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Analytics by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Policy Enforcement Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Analytics by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Security Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Iot Field Network Director by Cisco

Version Range Affected
To 4.11.0 (exclusive)
cpe:2.3:a:cisco:iot_field_network_director:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Container Platform by Redhat

cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certification For Red Hat Enterprise Linux by Redhat

cpe:2.3:a:redhat:certification_for_red_hat_enterprise_linux:9.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Traffic Server by Apache

Version Range Affected
From 8.0.0 (inclusive)
To 8.1.9 (exclusive)
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Migration Toolkit For Virtualization by Redhat

cpe:2.3:a:redhat:migration_toolkit_for_virtualization:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Node.Js by Nodejs

Version Range Affected
From 18.0.0 (inclusive)
To 18.18.2 (exclusive)
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Next by F5

cpe:2.3:a:f5:big-ip_next:20.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nginx Plus by F5

cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Developer Tools And Services by Redhat

cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone9:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Domain Name System by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Dev Spaces by Redhat

cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Core Services by Redhat

cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Acceleration Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Virtualization by Redhat

cpe:2.3:a:redhat:openshift_virtualization:4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Web Terminal by Redhat

cpe:2.3:a:redhat:web_terminal:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Proxygen by Facebook

Version Range Affected
To 2023.10.16.00 (exclusive)
cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Single Sign-On by Redhat

cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Kong Gateway by Konghq

Version Range Affected
To 3.4.2 (exclusive)
cpe:2.3:a:konghq:kong_gateway:*:*:*:*:enterprise:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

H2O by Dena

Version Range Affected
To 2023-10-10 (exclusive)
cpe:2.3:a:dena:h2o:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Fuse by Redhat

cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ddos Hybrid Defender by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Armeria by Linecorp

Version Range Affected
To 1.26.0 (exclusive)
cpe:2.3:a:linecorp:armeria:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
To 9.4.53 (exclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss A-Mq by Redhat

cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Fraud Protection Service by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Service Mesh by Redhat

cpe:2.3:a:redhat:openshift_service_mesh:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Service Telemetry Framework by Redhat

cpe:2.3:a:redhat:service_telemetry_framework:1.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Crosswork Zero Touch Provisioning by Cisco

Version Range Affected
To 6.0.0 (exclusive)
cpe:2.3:a:cisco:crosswork_zero_touch_provisioning:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Fraud Protection Service by F5

cpe:2.3:a:f5:big-ip_fraud_protection_service:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

Version Range Affected
From 8.5.0 (inclusive)
To 8.5.93 (inclusive)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Unified Contact Center Domain Manager by Cisco

cpe:2.3:a:cisco:unified_contact_center_domain_manager:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Sandboxed Containers by Redhat

cpe:2.3:a:redhat:openshift_sandboxed_containers:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Enterprise Application Platform by Redhat

cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Quay by Redhat

cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Cbl-Mariner by Microsoft

Version Range Affected
To 2023-10-11 (exclusive)
cpe:2.3:a:microsoft:cbl-mariner:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone11:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Traefik by Traefik

Version Range Affected
To 2.10.5 (exclusive)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Web Application Firewall by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Data Science by Redhat

cpe:2.3:a:redhat:openshift_data_science:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Fuse by Redhat

cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Unified Attendant Console Advanced by Cisco

cpe:2.3:a:cisco:unified_attendant_console_advanced:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Integration Camel K by Redhat

cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Envoy by Envoyproxy

cpe:2.3:a:envoyproxy:envoy:1.27.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 10 1607 by Microsoft

Version Range Affected
To 10.0.14393.6351 (exclusive)
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Fraud Protection Service by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Nx-Os by Cisco

Version Range Affected
From 10.4\(1\) (inclusive)
To 10.4\(2\) (exclusive)
cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ultra Cloud Core - Session Management Function by Cisco

Version Range Affected
To 2024.02.0 (exclusive)
cpe:2.3:a:cisco:ultra_cloud_core_-_session_management_function:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ultra Cloud Core - Policy Control Function by Cisco

Version Range Affected
To 2024.01.0 (exclusive)
cpe:2.3:a:cisco:ultra_cloud_core_-_policy_control_function:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Gitops by Redhat

cpe:2.3:a:redhat:openshift_gitops:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Secure Malware Analytics by Cisco

Version Range Affected
To 2.19.2 (exclusive)
cpe:2.3:a:cisco:secure_malware_analytics:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Http Server by Akka

Version Range Affected
To 10.5.3 (exclusive)
cpe:2.3:a:akka:http_server:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nghttp2 by Nghttp2

Version Range Affected
To 1.57.0 (exclusive)
cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ssl Orchestrator by F5

cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Visual Studio 2022 by Microsoft

Version Range Affected
From 17.4 (inclusive)
To 17.4.12 (exclusive)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 11 22H2 by Microsoft

Version Range Affected
To 10.0.22621.2428 (exclusive)
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Visibility And Reporting by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Acceleration Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Domain Name System by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Crosswork Data Gateway by Cisco

Version Range Affected
To 4.1.3 (exclusive)
cpe:2.3:a:cisco:crosswork_data_gateway:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 10.0.0 (inclusive)
To 10.0.17 (exclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 10 21H2 by Microsoft

Version Range Affected
To 10.0.19044.3570 (exclusive)
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ddos Hybrid Defender by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Fence Agents Remediation Operator by Redhat

cpe:2.3:a:redhat:fence_agents_remediation_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Visibility And Reporting by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Fedora by Fedoraproject

cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Data Grid by Redhat

cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Build Of Quarkus by Redhat

cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Web Application Firewall by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone8:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netty by Netty

Version Range Affected
To 4.1.100 (exclusive)
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Link Controller by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Unified Contact Center Enterprise by Cisco

cpe:2.3:a:cisco:unified_contact_center_enterprise:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Webaccelerator by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Run Once Duration Override Operator by Redhat

cpe:2.3:a:redhat:run_once_duration_override_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Http by Ietf

cpe:2.3:a:ietf:http:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Unified Contact Center Management Portal by Cisco

cpe:2.3:a:cisco:unified_contact_center_management_portal:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Advanced Firewall Manager by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Http2 by Golang

Version Range Affected
To 0.17.0 (exclusive)
cpe:2.3:a:golang:http2:*:*:*:*:*:go:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Fraud Protection Service by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Access Policy Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Link Controller by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Visual Studio 2022 by Microsoft

Version Range Affected
From 17.6 (inclusive)
To 17.6.8 (exclusive)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Carrier-Grade Nat by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows Server 2019 by Microsoft

cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Cost Management by Redhat

cpe:2.3:a:redhat:cost_management:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openstack Platform by Redhat

cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Grpc by Grpc

Version Range Affected
From 1.58.0 (inclusive)
To 1.58.3 (exclusive)
cpe:2.3:a:grpc:grpc:*:*:*:*:*:go:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Enterprise Chat And Email by Cisco

cpe:2.3:a:cisco:enterprise_chat_and_email:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Distributed Tracing by Redhat

cpe:2.3:a:redhat:openshift_distributed_tracing:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Linkerd by Linkerd

cpe:2.3:a:linkerd:linkerd:2.14.1:*:*:*:stable:kubernetes:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Unified Contact Center Enterprise - Live Data Server by Cisco

Version Range Affected
To 12.6.2 (exclusive)
cpe:2.3:a:cisco:unified_contact_center_enterprise_-_live_data_server:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Node Maintenance Operator by Redhat

cpe:2.3:a:redhat:node_maintenance_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Http2 by Kazu-Yamamoto

Version Range Affected
To 4.2.2 (exclusive)
cpe:2.3:a:kazu-yamamoto:http2:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Fedora by Fedoraproject

cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openstack Platform by Redhat

cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Fraud Protection Service by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Windows 10 1809 by Microsoft

Version Range Affected
To 10.0.17763.4974 (exclusive)
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Cryostat by Redhat

cpe:2.3:a:redhat:cryostat:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Global Traffic Manager by F5

Version Range Affected
From 13.1.0 (inclusive)
To 13.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Grpc by Grpc

Version Range Affected
To 1.59.2 (inclusive)
cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jenkins by Jenkins

Version Range Affected
To 2.414.2 (inclusive)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ssl Orchestrator by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Support For Spring Boot by Redhat

cpe:2.3:a:redhat:support_for_spring_boot:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Astra Control Center by Netapp

cpe:2.3:a:netapp:astra_control_center:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Websafe by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Domain Name System by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Apisix by Apache

Version Range Affected
To 3.6.1 (exclusive)
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Nx-Os by Cisco

Version Range Affected
To 10.2\(7\) (exclusive)
cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Integration Service Registry by Redhat

cpe:2.3:a:redhat:integration_service_registry:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Logging Subsystem For Red Hat Openshift by Redhat

cpe:2.3:a:redhat:logging_subsystem_for_red_hat_openshift:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Istio by Istio

Version Range Affected
From 1.18.0 (inclusive)
To 1.18.3 (exclusive)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Advanced Cluster Security by Redhat

cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 12.0.0 (inclusive)
To 12.0.2 (exclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openshift Secondary Scheduler Operator by Redhat

cpe:2.3:a:redhat:openshift_secondary_scheduler_operator:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Oncommand Insight by Netapp

cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

cpe:2.3:a:apache:tomcat:11.0.0:milestone3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nginx Plus by F5

Version Range Affected
From r25 (inclusive)
To r29 (exclusive)
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Traefik by Traefik

cpe:2.3:a:traefik:traefik:3.0.0:beta2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tomcat by Apache

Version Range Affected
From 9.0.0 (inclusive)
To 9.0.80 (inclusive)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Advanced Cluster Security by Redhat

cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux by Redhat

cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Websafe by F5

Version Range Affected
From 16.1.0 (inclusive)
To 16.1.4 (inclusive)
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Link Controller by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Application Security Manager by F5

Version Range Affected
From 14.1.0 (inclusive)
To 14.1.5 (inclusive)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Connected Mobile Experiences by Cisco

Version Range Affected
To 11.1 (exclusive)
cpe:2.3:a:cisco:connected_mobile_experiences:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Debian Linux by Debian

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Business Process Automation by Cisco

Version Range Affected
To 3.2.003.009 (exclusive)
cpe:2.3:a:cisco:business_process_automation:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Grpc by Grpc

cpe:2.3:a:grpc:grpc:1.57.0:-:*:*:*:go:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Contour by Projectcontour

Version Range Affected
To 2023-10-11 (exclusive)
cpe:2.3:a:projectcontour:contour:*:*:*:*:*:kubernetes:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Policy Enforcement Manager by F5

Version Range Affected
From 15.1.0 (inclusive)
To 15.1.10 (inclusive)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023…
https://access.redhat.com/security/cve/cve-2023-44487
https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-t…
https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-att…
https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-444…
https://blog.vespa.ai/cve-2023-44487/
https://bugzilla.proxmox.com/show_bug.cgi?id=4988
https://bugzilla.redhat.com/show_bug.cgi?id=2242803
https://bugzilla.suse.com/show_bug.cgi?id=1216123
https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be662…
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated…
https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel…
https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affecte…
https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-…
https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
https://github.com/advisories/GHSA-qppj-fm5r-hxr3
https://github.com/advisories/GHSA-vx74-f528-fxqg
https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
https://github.com/akka/akka-http/issues/4323
https://github.com/alibaba/tengine/issues/1872
https://github.com/apache/apisix/issues/10320
https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/m…
https://github.com/apache/httpd-site/pull/10
https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2
https://github.com/apache/trafficserver/pull/10564
https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
https://github.com/Azure/AKS/issues/3947
https://github.com/bcdannyboy/CVE-2023-44487
https://github.com/caddyserver/caddy/issues/5877
https://github.com/caddyserver/caddy/releases/tag/v2.7.5
https://github.com/dotnet/announcements/issues/277
https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/re…
https://github.com/eclipse/jetty.project/issues/10679
https://github.com/envoyproxy/envoy/pull/30055
https://github.com/etcd-io/etcd/issues/16740
https://github.com/facebook/proxygen/pull/466
https://github.com/golang/go/issues/63417
https://github.com/grpc/grpc-go/pull/6703
https://github.com/h2o/h2o/pull/3291
https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
https://github.com/haproxy/haproxy/issues/2312
https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/m…
https://github.com/junkurihara/rust-rpxy/issues/97
https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6d…
https://github.com/kazu-yamamoto/http2/issues/93
https://github.com/Kong/kong/discussions/11741
https://github.com/kubernetes/kubernetes/pull/121120
https://github.com/line/armeria/pull/5232
https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6f…
https://github.com/micrictor/http2-rst-stream
https://github.com/microsoft/CBL-Mariner/pull/6381
https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
https://github.com/nghttp2/nghttp2/pull/1961
https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
https://github.com/ninenines/cowboy/issues/1615
https://github.com/nodejs/node/pull/50121
https://github.com/openresty/openresty/issues/930
https://github.com/opensearch-project/data-prepper/issues/3474
https://github.com/oqtane/oqtane.framework/discussions/3367
https://github.com/projectcontour/contour/pull/5826
https://github.com/tempesta-tech/tempesta/issues/1986
https://github.com/varnishcache/varnish-cache/issues/3996
https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
https://istio.io/latest/news/security/istio-security-2023-004/
https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html
https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html
https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapr…
https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html
https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLP…
https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-strea…
https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denia…
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
https://my.f5.com/manage/s/article/K000137106
https://netty.io/news/2023/10/10/4-1-100-Final.html
https://news.ycombinator.com/item?id=37830987
https://news.ycombinator.com/item?id=37830998
https://news.ycombinator.com/item?id=37831062
https://news.ycombinator.com/item?id=37837043
https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights…
https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffec…
https://security.gentoo.org/glsa/202311-09
https://security.netapp.com/advisory/ntap-20231016-0001/
https://security.netapp.com/advisory/ntap-20240426-0007/
https://security.netapp.com/advisory/ntap-20240621-0006/
https://security.netapp.com/advisory/ntap-20240621-0007/
https://security.paloaltonetworks.com/CVE-2023-44487
https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
https://ubuntu.com/security/CVE-2023-44487
https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-…
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerabil…
https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever…
https://www.debian.org/security/2023/dsa-5521
https://www.debian.org/security/2023/dsa-5522
https://www.debian.org/security/2023/dsa-5540
https://www.debian.org/security/2023/dsa-5549
https://www.debian.org/security/2023/dsa-5558
https://www.debian.org/security/2023/dsa-5570
https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-…
https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-product…
https://www.openwall.com/lists/oss-security/2023/10/10/6
https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack
https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-…
http://www.openwall.com/lists/oss-security/2023/10/13/4
http://www.openwall.com/lists/oss-security/2023/10/13/9
http://www.openwall.com/lists/oss-security/2023/10/18/4
http://www.openwall.com/lists/oss-security/2023/10/18/8
http://www.openwall.com/lists/oss-security/2023/10/19/6
http://www.openwall.com/lists/oss-security/2023/10/20/8
http://www.openwall.com/lists/oss-security/2025/08/13/6
https://access.redhat.com/security/cve/cve-2023-44487
https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-t…
https://aws.amazon.com/security/security-bulletins/AWS-2023-011/
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-att…
https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-444…
https://blog.vespa.ai/cve-2023-44487/
https://bugzilla.proxmox.com/show_bug.cgi?id=4988
https://bugzilla.redhat.com/show_bug.cgi?id=2242803
https://bugzilla.suse.com/show_bug.cgi?id=1216123
https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be662…
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated…
https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel…
https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affecte…
https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve
https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-…
https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
https://github.com/advisories/GHSA-qppj-fm5r-hxr3
https://github.com/advisories/GHSA-vx74-f528-fxqg
https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
https://github.com/akka/akka-http/issues/4323
https://github.com/alibaba/tengine/issues/1872
https://github.com/apache/apisix/issues/10320
https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/m…
https://github.com/apache/httpd-site/pull/10
https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2
https://github.com/apache/trafficserver/pull/10564
https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
https://github.com/Azure/AKS/issues/3947
https://github.com/bcdannyboy/CVE-2023-44487
https://github.com/caddyserver/caddy/issues/5877
https://github.com/caddyserver/caddy/releases/tag/v2.7.5
https://github.com/dotnet/announcements/issues/277
https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/re…
https://github.com/eclipse/jetty.project/issues/10679
https://github.com/envoyproxy/envoy/pull/30055
https://github.com/etcd-io/etcd/issues/16740
https://github.com/facebook/proxygen/pull/466
https://github.com/golang/go/issues/63417
https://github.com/grpc/grpc-go/pull/6703
https://github.com/grpc/grpc/releases/tag/v1.59.2
https://github.com/h2o/h2o/pull/3291
https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
https://github.com/haproxy/haproxy/issues/2312
https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/m…
https://github.com/junkurihara/rust-rpxy/issues/97
https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6d…
https://github.com/kazu-yamamoto/http2/issues/93
https://github.com/Kong/kong/discussions/11741
https://github.com/kubernetes/kubernetes/pull/121120
https://github.com/line/armeria/pull/5232
https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6f…
https://github.com/micrictor/http2-rst-stream
https://github.com/microsoft/CBL-Mariner/pull/6381
https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
https://github.com/nghttp2/nghttp2/pull/1961
https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
https://github.com/ninenines/cowboy/issues/1615
https://github.com/nodejs/node/pull/50121
https://github.com/openresty/openresty/issues/930
https://github.com/opensearch-project/data-prepper/issues/3474
https://github.com/oqtane/oqtane.framework/discussions/3367
https://github.com/projectcontour/contour/pull/5826
https://github.com/tempesta-tech/tempesta/issues/1986
https://github.com/varnishcache/varnish-cache/issues/3996
https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
https://istio.io/latest/news/security/istio-security-2023-004/
https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html
https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html
https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html
https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html
https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLP…
https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-strea…
https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denia…
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
https://my.f5.com/manage/s/article/K000137106
https://netty.io/news/2023/10/10/4-1-100-Final.html
https://news.ycombinator.com/item?id=37830987
https://news.ycombinator.com/item?id=37830998
https://news.ycombinator.com/item?id=37831062
https://news.ycombinator.com/item?id=37837043
https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights…
https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffec…
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/c…
https://security.gentoo.org/glsa/202311-09
https://security.netapp.com/advisory/ntap-20231016-0001/
https://security.netapp.com/advisory/ntap-20240426-0007/
https://security.netapp.com/advisory/ntap-20240621-0006/
https://security.netapp.com/advisory/ntap-20240621-0007/
https://security.paloaltonetworks.com/CVE-2023-44487
https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
https://ubuntu.com/security/CVE-2023-44487
https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-…
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerabil…
https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever…
https://www.debian.org/security/2023/dsa-5521
https://www.debian.org/security/2023/dsa-5522
https://www.debian.org/security/2023/dsa-5540
https://www.debian.org/security/2023/dsa-5549
https://www.debian.org/security/2023/dsa-5558
https://www.debian.org/security/2023/dsa-5570
https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-…
https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-product…
https://www.openwall.com/lists/oss-security/2023/10/10/6
https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack
https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/
http://www.openwall.com/lists/oss-security/2023/10/10/6
http://www.openwall.com/lists/oss-security/2023/10/10/7
http://www.openwall.com/lists/oss-security/2023/10/13/4
http://www.openwall.com/lists/oss-security/2023/10/13/9
http://www.openwall.com/lists/oss-security/2023/10/18/4
http://www.openwall.com/lists/oss-security/2023/10/18/8
http://www.openwall.com/lists/oss-security/2023/10/19/6
http://www.openwall.com/lists/oss-security/2023/10/20/8