CVE-2023-45802 is an incomplete fix for CVE-2023-44487 in Apache HTTP Server mod_http2. When an HTTP/2 client resets a stream with an RST frame, request memory is not immediately reclaimed and is instead retained until the connection closes. An attacker can repeatedly issue new requests and reset them while keeping the connection active, causing retained memory to accumulate.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small single-purpose Python exploit repo containing one executable script, CVE-2023-45802.py, plus an MIT LICENSE file. The script is a proof-of-concept/operational denial-of-service exploit for CVE-2023-45802 targeting Apache HTTP Server HTTP/2 implementations described in the header as versions 2.4.17 through 2.4.57, with Apache/2.4.52 (Ubuntu) used as the example vulnerable target. The exploit structure is straightforward: a class named HTTP2MemoryExhaustion manages connection setup, attack execution, keep-alive behavior, and cleanup. In connect(), it opens a raw TCP socket to the target on port 443, wraps it in TLS, disables certificate validation, and requires ALPN negotiation of 'h2'. It then initializes an HTTP/2 client using the Python h2 library. In rapid_reset_attack(), it repeatedly allocates new HTTP/2 stream IDs, sends HEADERS for a GET / request, and immediately resets each stream with RST_STREAM using the CANCEL error code. This is intended to trigger memory exhaustion on vulnerable servers. In keep_alive(), it sends periodic HTTP/2 PING frames and reads server responses so the connection remains open, which the author notes is important to delay memory deallocation. The multi_thread_attack() helper launches several daemon threads, each running a separate attack connection, increasing total stream volume and impact. Main exploit capabilities: establish HTTP/2-over-TLS sessions, generate large numbers of streams, immediately cancel them, and sustain connections to maximize retained server memory. The script is not a scanner or detector; it is an active exploit for service degradation/DoS. It does not deliver code execution or a shell payload. The only fingerprintable target values hardcoded in the script are the demo host archive.ubuntu.com, TCP port 443, ALPN protocol h2, and HTTP path '/'. The script’s default configuration uses 5 threads and 20,000 streams per thread, with a 5-second warning delay before launching.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-reachable, high-complexity vulnerability with no confidentiality or integrity impact but high availability impact, according to the supplied CVSS v3 vector.
A mod_http2 memory-exhaustion vulnerability triggered by reset requests; it corrects an incomplete fix for CVE-2023-44487.
A memory-exhaustion vulnerability in mod_http2 caused by reset requests; it corrects an incomplete fix for CVE-2023-44487.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.