Apache HTTP Server: DoS in HTTP/2 with initial windows size 0
CVE-2023-43622
What is CVE-2023-43622?
A vulnerability in Apache HTTP Server allows an attacker to create an HTTP/2 connection with an initial window size of 0, leading to indefinite blocking of connection handling. This can exhaust server worker resources, resembling the characteristics of a 'slow loris' attack. The issue impacts versions between 2.4.55 and 2.4.57 and has been addressed in version 2.4.58, which ensures proper termination of such connections after the defined timeout. It is highly recommended for users to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache HTTP Server 2.4.55 <= 2.4.57
References
EPSS Score
59% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved