CVE-2023-45802
Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST
- Published
- Oct 23, 2023
- Updated
- Oct 14, 2024
- Assigning CNA
- apache
- Evidence observed
- Aug 14, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HLow · next 30 days
- Percentile
- 86.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that. This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During "normal" HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out. Users are recommended to upgrade to version 2.4.58, which fixes the issue.
Sources
1- CVE-2023-45802Exploit
CVE-2023-45802 - Apache HTTP/2 Memory Exhaustion DoS Apache versions: 2.4.17 through 2.4.57 Target: Apache/2.4.52 (Ubuntu) - VULNERABLE MehranTurk (M.T) WARNING: For authorized testing in LAB environment only!
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.