HTTP2 Rapid Reset DoS

Strike ID:
E23-gy071
CVSS:
7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
1
Year:
2023

Description

This strike simulates a denial of service attack by exploiting an HTTP/2 protocol vulnerability. The vulnerability is caused by the way that HTTP/2 handles request cancellation. Specifically, a client request cancellation can be initiated to rapidly reset a large number of streams. If the server is unable to process the reset requests quickly enough, it is possible for large enough queue to lead to resource exhaustion on the server causing a denial of service condition to occur.

CVE

References