VDB

ALPINE-CVE-2023-44487

ALPINE-CVE-2023-44487 PUBLISHED CVSS 7.5 HIGH

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.17nghttp21.48.0-r0, 1.47.0-r0, 1.44.0-r2
Alpine:v3.21varnish4.0.2-r2, 4.0.2-r1, 4.0.2-r0
Alpine:v3.24varnish0, 0, 0
Alpine:v3.20nginx1.14.0-r2, 1.14.0-r1, 1.14.0-r0
Alpine:v3.18nginx1.24.0-r2, 1.12.2-r2, 0
Alpine:v3.22nghttp21.3.2-r0, 1.29.0-r0, 1.28.0-r0
Alpine:v3.17lighttpd1.4.20-r1, 1.4.65-r0, 1.4.39-r1
Alpine:v3.19varnish3.0.0-r2, 3.0.2-r0, 3.0.2-r1
Alpine:v3.19nghttp21.35.1-r0, 1.37.0-r0, 1.37.0-r1
Alpine:v3.15lighttpd1.4.49-r0, 1.4.47-r1, 1.4.47-r0
Alpine:v3.23nodejs0, 0, 0
Alpine:v3.22nodejs0, 0, 0
Alpine:v3.18varnish3.0.3-r0, 3.0.2-r7, 3.0.2-r6
Alpine:v3.22varnish3.0.4-r0, 0, 0
Alpine:v3.23varnish3.0.2-r7, 3.0.3-r1, 3.0.3-r2
Alpine:v3.15nginx1.14.1-r0, 1.18.0-r8, 1.2.3-r0
Alpine:v3.20nodejs0, 0, 0
Alpine:v3.21nodejs0, 0, 0
Alpine:v3.24nghttp20, 0, 0
Alpine:v3.18nghttp21.21.1-r0, 1.28.0-r0, 1.23.1-r0

…and 19 more

Timeline

  • Oct 10, 2023 CVE Published
  • Aug 7, 2026 CVE Updated
  • Aug 8, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›