CVE-2024-27983 is a race condition in the Node.js HTTP/2 server's handling of HTTP/2 CONTINUATION frames. When headers are being processed and retained in nghttp2 memory, a client can abruptly close its TCP connection, invoking destruction of the Http2Session while header-frame processing remains in progress. This can leave data in nghttp2 memory after reset and render the HTTP/2 server completely unavailable using a small number of crafted HTTP/2 frame packets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a Rust workspace implementing an HTTP/2 stress-testing and attack-simulation framework (“Phoenix”) with raw frame-level control. Structure/purpose: - phoenix-cli/: Main CLI binary `phoenix` (clap-based) to run attacks (`phoenix attack <type> --target ...`) and a `scan` subcommand (implementation not fully shown due to truncation). Produces terminal summaries and optional JSON reports. - phoenix-attacks/: Core attack modules implementing an `Attack` trait. Modules craft and send raw HTTP/2 frames over TLS using phoenix-core’s `RawH2Connection`, plus a “universal” adaptive module using the `h2` crate. - phoenix-core/: Low-level TLS + raw HTTP/2 frame read/write, frame builders (SETTINGS, HEADERS, RST_STREAM, PING, CONTINUATION, etc.), and a connection pool. Includes a no-op TLS verifier for testing. - phoenix-metrics/: Atomic counters + HDRHistogram latency tracking and a ratatui terminal dashboard. - phoenix-report/: JSON report writer and terminal summary formatting. - target-server/: Reference nginx+Python analytics target environment for measuring HTTP/2 stream rates via access logs and broadcasting live stats over WebSocket. Exploit/attack capabilities (network DoS/stress): - Rapid Reset (CVE-2023-44487): sends HEADERS then immediately RST_STREAM at very high rates across multiple connections to burn server CPU/memory on stream lifecycle churn. - CONTINUATION flood (CVE-2024-27983 family): sends HEADERS without END_HEADERS then many CONTINUATION frames to force server buffering/processing of oversized header blocks. - HPACK bomb: manipulates HPACK dynamic table by inserting a large header value and referencing it many times to amplify decompression memory usage. - SETTINGS flood: sends many SETTINGS frames without waiting for ACKs to overload server frame queues/ACK handling. - PING flood: sends many PING frames (optionally tracking ACKs) to consume server resources. - Load test: legitimate GET request generation over raw HTTP/2 for throughput/latency measurement. - Universal module: probes server (ALPN/SETTINGS) and adapts behavior; includes a rapid-reset-like mode using `h2` stream resets. Notable security-relevant implementation details: - Multiple modules construct URLs as `https://<host>:<port>` and rely on ALPN h2. - `phoenix-core/connection.rs` and `phoenix-attacks/universal.rs` implement a dangerous/no-op certificate verifier (accepts any cert), enabling testing against self-signed targets but also reducing safety if misused. Overall, this is an operational, multi-module HTTP/2 attack/stress framework rather than a single exploit PoC; it is designed to generate protocol-accurate abusive HTTP/2 frame patterns and measure their effects.
Phoenix is a Rust workspace implementing an HTTP/2 stress-testing / attack-simulation toolkit that operates at the raw frame level over TLS (ALPN h2). It is not a Metasploit/Nuclei-style framework module; it is a standalone multi-crate project. Repository structure (35 files): - phoenix-core/: low-level primitives for HTTP/2 over TLS - connection.rs: establishes TCP+TLS connections, enforces ALPN 'h2', sends HTTP/2 preface and SETTINGS handshake, and provides raw frame read/write. - frame.rs: constructs/parses HTTP/2 frames (SETTINGS, HEADERS, RST_STREAM, PING, CONTINUATION, etc.) and includes minimal HPACK encoding helpers. - pool.rs/config.rs/error.rs: connection pooling, target/attack configuration validation, and error types. - phoenix-attacks/: attack modules implementing an Attack trait with AttackContext/AttackResult - rapid_reset.rs (CVE-2023-44487): repeatedly sends a minimal GET HEADERS frame then immediately RST_STREAM on many streams across multiple connections; optional RPS rate limiting via governor. - continuation_flood.rs (CVE-2024-27983 family): sends HEADERS without END_HEADERS then many CONTINUATION frames (optionally ending with END_HEADERS) to force server buffering/processing. - hpack_bomb.rs: sends SETTINGS to enlarge header table and crafts HPACK blocks that add a large dynamic-table entry then reference it many times to amplify decompression memory/CPU. - settings_flood.rs: high-rate SETTINGS frames without waiting for ACKs to stress server queues/ACK handling. - ping_flood.rs: high-rate PING frames; optionally waits for ACKs to measure handling/latency. - load_test.rs: placeholder that currently errors out (notes Rust 1.83+ requirement), indicating the “legitimate load test” path is not operational in the provided snapshot. - phoenix-metrics/: atomic counters + HDRHistogram latency tracking and a ratatui/crossterm live dashboard. - phoenix-report/: JSON report writer and terminal summary printer. - phoenix-cli/: clap-based CLI skeleton with subcommands Attack/Scan/Version; in the provided code, attack execution appears largely “simulated” (prints progress, builds a MetricsSnapshot) rather than wiring into phoenix-attacks’ real network modules. - index.html: marketing/landing page content (not part of exploit logic). - test_phoenix.sh: build/test helper script. Exploit/attack capabilities: - Network-based HTTP/2 DoS/stress generation over TLS against a user-supplied target host/port. - Implements multiple protocol-abuse patterns (Rapid Reset, CONTINUATION flood, HPACK bomb, SETTINGS flood, PING flood) by crafting and sending raw HTTP/2 frames. - Concurrency: multiple parallel connections/tasks; stream ID management; optional rate limiting (Rapid Reset). - Telemetry: metrics collection (requests/frames, errors, bytes, latency histogram) and reporting. Notable targeting/assumptions: - Targets are generic HTTP/2 servers; Rapid Reset explicitly references CVE-2023-44487; CONTINUATION flood references CVE-2024-27983 family. - Core TLS connector verifies ALPN is 'h2' and defaults to HTTPS/443; config validation in phoenix-core requires https scheme. Fingerprintable endpoints/observables: - No hardcoded attacker-controlled C2/IPs/domains; endpoints are user-provided targets. - Only example URLs (https://example.com, https://test.com) and repository links appear in docs/tests. - Local file observables include report output paths (user-specified) and standard Rust build artifacts; no registry keys or OS persistence behavior present.
This repository provides a proof-of-concept (POC) exploit for CVE-2024-27983, a continuation flood vulnerability in Node.js HTTP/2 servers. The structure includes: - Vulnerable server code (`server-nossl.js`) that runs an HTTP/2 server without SSL on port 7777, which is susceptible to the attack. - A secure server (`server.js`) using SSL, which is not vulnerable. - A Go-based exploit (`exploit/exploit2.go`) that repeatedly establishes TCP connections to the target server and sends crafted HTTP/2 frames (headers and continuation frames) to trigger the vulnerability. The exploit is run with `go run ./exploit2.go -address [server]`. - A client script (`client.js`) for testing the server's normal operation over HTTPS. - Supporting files for Docker deployment, certificate generation, and a Fastify example server. The main exploit capability is to demonstrate and test the HTTP/2 continuation flood vulnerability, potentially leading to denial of service on affected servers. The repository is structured for easy setup and testing in a local environment, with clear separation between vulnerable and non-vulnerable server implementations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An important-severity network-accessible vulnerability affecting the Alma Linux 9.2 security-check context, with low attack complexity, no privileges or user interaction required, low integrity impact, and high availability impact.
A denial-of-service vulnerability in Node.js HTTP/2 handling involving CONTINUATION frames, residual nghttp2 memory, and a race condition during abrupt connection closure.
A high-severity denial-of-service vulnerability in the Node.js HTTP/2 server that can be triggered with malformed HTTP requests.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.