HTTP2: HTTP/2 Rapid Reset
This signature detects attempts to exploit a known vulnerability against HTTP/2. A successful attack can result in a denial-of-service condition.
Extended Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Affected Products
Cisco crosswork_data_gateway
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Konghq
Istio
Nghttp2
Projectcontour
Jenkins
Netapp
Varnish_cache_project
Linecorp
Grpc
Amazon
Apache
Envoyproxy
Netty
Ietf
Kazu-yamamoto
Eclipse
Caddyserver
Openresty
Cisco
Dena
Akka
Microsoft
Apple
Linkerd
F5
Redhat
Nodejs
Traefik
Fedoraproject
Debian
Golang