Database/Container, Kubernetes & orchestration
Envoy: "HTTP/2 Rapid Reset": stream-cancellation flood exhausts server resources
CVE-2023-44487Container, Kubernetes & orchestrationcurated
Impact
"HTTP/2 Rapid Reset": stream-cancellation flood exhausts server resources. Exploited in the wild at massive scale in late 2023
Who can reach it
Unauthenticated network
What to do
Upgrade Envoy, Istio, Traefik, ingress-nginx and the Go runtime in every Go-based controller. Broad, multi-component rollout; no GPU drain
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.