Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/bcdannyboy/cve-2023-44487
Vulnerability ScannersExploitationWeb Security
GitHubbcdannyboy/cve-2023-44487

CVE-2023-44487

Non-invasive HTTP/2 vulnerability scanner for CVE-2023-44487 that detects exploitable stream reset conditions by testing protocol downgrade and connection stream behavior.

View Repository
2464732 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-44487

Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487

This tool checks to see if a website is vulnerable to CVE-2023-44487 completely non-invasively.

  1. The tool checks if a web server accepts HTTP/2 requests without downgrading them
  2. If the web server accepts and does not downgrade HTTP/2 requests the tool attempts to open a connection stream and subsequently reset it
  3. If the web server accepts the creation and resetting of a connection stream then the server is definitely vulnerable, if it only accepts HTTP/2 requests but the stream connection fails it may be vulnerable if the server-side capabilities are enabled.

To run,

root@kitploit:~
$ python3 -m pip install -r requirements.txt

$ python3 cve202344487.py -i input_urls.txt -o output_results.csv

You can also specify an HTTP proxy to proxy all the requests through with the --proxy flag

root@kitploit:~
$ python3 cve202344487.py -i input_urls.txt -o output_results.csv --proxy http://proxysite.com:1234

The script outputs a CSV file with the following columns

  • Timestamp: a timestamp of the request
  • Source Internal IP: The internal IP address of the host sending the HTTP requests
  • Source External IP: The external IP address of the host sending the HTTP requests
  • URL: The URL being scanned
  • Vulnerability Status: "VULNERABLE"/"LIKELY"/"POSSIBLE"/"SAFE"/"ERROR"
  • Error/Downgrade Version: The error or the version the HTTP server downgrades the request to

Note: "Vulnerable" in this context means that it is confirmed that an attacker can reset the a stream connection without issue, it does not take into account implementation-specific or volume-based detections

Dockerized

Build

root@kitploit:~
$ docker build -t py-cve-2023-44487 .

Run:

root@kitploit:~
$ docker run --rm -v /path/to/urls:/shared py-cve-2023-44487 -i /shared/input_urls.txt -o /shared/output_results.csv
Download Tool